CompTIA Security+ (SY0-701)Security ArchitectureHard

A multinational corporation processes customer data from the European Union in a cloud provider's data center located in another country. Legal counsel raises concerns that this may violate regulations requiring certain data to remain within specific geographic or legal boundaries. Which concept does this scenario primarily concern?

  1. AData sovereignty
  2. BData classification
  3. CData tokenization
  4. DData masking
Show answer & explanation

Correct answer: A. Data sovereignty

Data sovereignty refers to the principle that data is subject to the laws and regulations of the country or region in which it is collected or resides, and processing or storing it outside that jurisdiction can create legal compliance issues, as described in the scenario.

Why the other options are wrong

  • B. Data classification categorizes data sensitivity but doesn't address legal jurisdiction.
  • C. Tokenization replaces sensitive values with tokens, unrelated to jurisdictional data location.
  • D. Data masking obscures values for privacy, unrelated to geographic legal requirements.

Data Sovereignty

The concept that data is subject to the laws of the country or jurisdiction where it is physically located or collected, affecting where it can legally be stored or processed.

  • Relevant to regulations like GDPR for EU citizen data
  • May require data residency within specific borders
  • Cloud providers often offer region-specific data centers to comply

Memory trick: Data obeys the laws of the land it lives on.

More Security Architecture questions