CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a system for a global enterprise that needs to process and store customer data in various international regions. Due to strict data residency regulations in different countries, the system must ensure that data originating from a specific country remains physically within that country's borders. Which architectural pattern should the architect implement to meet this compliance requirement?
- ARegional Data Silos
- BContent Delivery Network (CDN)
- CCentralized Data Lake
- DGlobal Load Balancing
Show answer & explanationAnswer & explanation
Correct answer: A. Regional Data Silos
Regional data silos, or data localization, explicitly ensure that data is stored and processed within the geographical boundaries of its origin, directly addressing strict data residency requirements. Each region operates independently with its own data storage.
Why the other options are wrong
- B. A CDN caches content closer to users for performance, but it's not designed to enforce data residency for primary data storage and processing.
- C. A centralized data lake would consolidate data into one location, directly violating data residency requirements across multiple countries.
- D. Global load balancing distributes traffic but does not guarantee where data is physically stored or processed, potentially violating data residency.
Regional Data Silos (Data Residency by Design)
An architectural approach where data is intentionally confined to specific geographic regions or countries to comply with local data residency regulations.
- Ensures data remains within defined jurisdictional boundaries.
- Often requires separate infrastructure, databases, and application deployments per region.
- Can increase operational complexity and cost but is necessary for compliance.
Memory trick: Local Laws, Local Data: Silo It!