CompTIA Cloud+ (CV0-004)SecurityHard

A global organization is implementing a new cloud-based data analytics platform. Due to strict regulatory requirements in various regions, certain sensitive datasets must be stored and processed exclusively within specific geographic boundaries. The organization also needs to ensure that data access is restricted based on the user's location. Which concept directly addresses these requirements?

  1. AData masking
  2. BData sovereignty
  3. CData loss prevention (DLP)
  4. DGeo-fencing
Show answer & explanation

Correct answer: B. Data sovereignty

Data sovereignty refers to the idea that data is subject to the laws and regulations of the country or region where it is collected or processed. This directly addresses the requirement for sensitive datasets to be stored and processed exclusively within specific geographic boundaries due to regulatory compliance, and implicitly impacts access based on location.

Why the other options are wrong

  • A. Data masking techniques obscure sensitive data to protect it, but do not dictate where the data is stored or processed geographically.
  • C. DLP focuses on preventing unauthorized transmission of sensitive data, not primarily on its geographic storage or processing location.
  • D. Geo-fencing is a technology that defines a virtual geographic boundary and triggers an action when a device enters or leaves it; while related to location, it's a mechanism, not the overarching legal concept of data residency.

Data Sovereignty

The concept that digital data is subject to the laws and regulations of the country or region where it is stored or processed, often impacting data residency and cross-border data transfers.

  • Data is subject to local laws where it resides.
  • Crucial for regulatory compliance (e.g., GDPR, CCPA).
  • Influences choice of cloud regions and data transfer policies.

Memory trick: Sovereignty: Data's country, data's rules.

More Security questions