CompTIA Security+ (SY0-701)Security ArchitectureHard
A multinational corporation processes customer data from the European Union in a cloud provider's data center located in another country. Legal counsel raises concerns that this may violate regulations requiring certain data to remain within specific geographic or legal boundaries. Which concept does this scenario primarily concern?
- AData sovereignty
- BData classification
- CData tokenization
- DData masking
Show answer & explanationAnswer & explanation
Correct answer: A. Data sovereignty
Data sovereignty refers to the principle that data is subject to the laws and regulations of the country or region in which it is collected or resides, and processing or storing it outside that jurisdiction can create legal compliance issues, as described in the scenario.
Why the other options are wrong
- B. Data classification categorizes data sensitivity but doesn't address legal jurisdiction.
- C. Tokenization replaces sensitive values with tokens, unrelated to jurisdictional data location.
- D. Data masking obscures values for privacy, unrelated to geographic legal requirements.
Data Sovereignty
The concept that data is subject to the laws of the country or jurisdiction where it is physically located or collected, affecting where it can legally be stored or processed.
- Relevant to regulations like GDPR for EU citizen data
- May require data residency within specific borders
- Cloud providers often offer region-specific data centers to comply
Memory trick: Data obeys the laws of the land it lives on.