SY0-701 · Question #548
A company processes and stores sensitive data on its own systems. Which of the following steps should the company take first to ensure compliance with privacy regulations?
The correct answer is A. Implement access controls and encryption. Implementing access controls and encryption (A) is the foundational first step because privacy regulations like GDPR and HIPAA require organizations to technically safeguard sensitive data at rest and in transit before other measures can be meaningful - you must protect the…
Question
A company processes and stores sensitive data on its own systems. Which of the following steps should the company take first to ensure compliance with privacy regulations?
Options
- AImplement access controls and encryption.
- BDevelop and provide training on data protection policies.
- CCreate incident response and disaster recovery plans.
- DPurchase and install security software.
How the community answered
(41 responses)- A73% (30)
- B15% (6)
- C5% (2)
- D7% (3)
Explanation
Implementing access controls and encryption (A) is the foundational first step because privacy regulations like GDPR and HIPAA require organizations to technically safeguard sensitive data at rest and in transit before other measures can be meaningful - you must protect the data itself before building processes around it.
Why the distractors fall short:
- B (Training) - Training employees on policies is important, but policies without technical controls in place leave data exposed; training supports enforcement of controls, not a substitute.
- C (Incident response/DR plans) - These plans assume you already have security measures protecting data; planning for breaches before securing the data puts the cart before the horse.
- D (Security software) - Purchasing software is too generic and implementation-focused; access controls and encryption are the specific technical requirements regulators mandate, not just "security software" broadly.
Memory tip: Think "Protect first, then plan, then train, then tool." Regulators care most about whether the data itself is locked down (access controls + encryption = the lock on the vault). Everything else - policies, training, software purchases - supports that core protection but can't replace it.
Topics
Community Discussion
No community discussion yet for this question.