CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium

A company is subject to strict data residency laws, requiring all customer data to remain within specific geographic boundaries. They are considering using a cloud-based database service. Which architectural consideration is MOST critical to ensure compliance with these laws?

  1. AImplementing strong encryption for data in transit and at rest.
  2. BEnsuring the cloud provider offers multi-factor authentication (MFA).
  3. CConfiguring granular role-based access control (RBAC) within the database.
  4. DVerifying the cloud provider's data center locations and data replication policies.
Show answer & explanation

Correct answer: D. Verifying the cloud provider's data center locations and data replication policies.

Data residency laws specifically mandate that data must be stored and processed within certain geographical borders. Verifying the cloud provider's data center locations and their data replication policies (e.g., ensuring data is not replicated outside the required region) is paramount to ensure compliance.

Why the other options are wrong

  • A. Encryption is crucial for security but doesn't guarantee data stays within a specific geographic region.
  • B. MFA enhances access security but does not address where the data is physically stored or replicated.
  • C. RBAC controls user access but has no bearing on the physical location of the data.

Data Residency

A legal or regulatory requirement that dictates where an organization's data must be stored and processed, typically within specific geographic boundaries.

  • Mandated by various international and national laws (e.g., GDPR, CCPA).
  • Requires careful selection of cloud providers and data center regions.
  • Impacts data replication, backup strategies, and disaster recovery planning.

Memory trick: Cloud compliance needs a map for data and rules.

More Data and Database Security questions