CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium
A project involves developing a new mobile application that will collect and process user location data. To ensure data privacy and compliance with regulations like CCPA, which technical safeguard is most appropriate for protecting this sensitive personal data?
- AEnsuring the development team uses multi-factor authentication for their cloud development environment.
- BImplementing robust physical security measures for the mobile devices.
- CEncrypting location data at rest and in transit using industry-standard protocols.
- DProviding users with a detailed privacy policy document upon app installation.
Show answer & explanationAnswer & explanation
Correct answer: C. Encrypting location data at rest and in transit using industry-standard protocols.
The scenario focuses on protecting 'sensitive personal data' (user location) collected by a mobile app, specifically mentioning data privacy and compliance (CCPA). Encryption at rest and in transit is a fundamental technical safeguard for protecting data confidentiality against unauthorized access, aligning directly with privacy requirements for sensitive data.
Why the other options are wrong
- A. MFA for the development environment protects developer access, not the user's data once collected by the app.
- B. Physical security of the end-user's device is beyond the app developer's direct control and doesn't protect data once it leaves the device.
- D. A privacy policy is a legal document for transparency, but not a technical safeguard for data protection itself.
Data Encryption
The process of transforming plain text data into a coded format (ciphertext) to prevent unauthorized access.
- Protects data confidentiality.
- Can be applied to data at rest (stored) and data in transit (over networks).
- Essential for meeting many data privacy regulations.
Memory trick: Data Protection: Encrypt, Access, Audit your Assets.