CompTIA Cloud+ (CV0-004)SecurityEasy
A compliance officer is reviewing the data residency requirements for a new cloud-based application. The application will process sensitive customer data, and regulations dictate that this data MUST remain within specific geographic boundaries. Which aspect of cloud infrastructure is MOST critical to ensure compliance?
- AUtilizing multi-factor authentication (MFA) for all user access.
- BImplementing end-to-end encryption for all data in transit.
- CDeploying resources within the appropriate cloud region or availability zone.
- DSelecting a cloud provider with robust DDoS protection.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploying resources within the appropriate cloud region or availability zone.
Data residency requirements are met by ensuring that data is physically stored and processed within specified geographic boundaries, which is determined by the cloud region or availability zone where resources are deployed.
Why the other options are wrong
- A. MFA enhances access security but has no bearing on the physical location of data.
- B. End-to-end encryption protects data confidentiality during transit but does not dictate where the data ultimately resides at rest.
- D. DDoS protection is a security feature, but it does not address data residency requirements.
Data Residency
The requirement for data to be stored and processed within specific geographic boundaries, often dictated by legal or regulatory compliance.
- Crucial for many industry and government regulations.
- Determined by the physical location of data centers.
- Cloud regions and availability zones are key to achieving this.
Memory trick: Residency is about the house, not the locks or the road.