CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium

A project involves integrating a new customer relationship management (CRM) system with an existing enterprise resource planning (ERP) system. Both systems are cloud-based, but managed by different vendors. The project manager needs to ensure that data exchanges between these systems comply with strict data privacy regulations. Which strategy best addresses this data privacy and compliance concern during the integration?

  1. ASchedule daily data backups for both the CRM and ERP systems.
  2. BUtilize a common identity provider for single sign-on across both platforms.
  3. CEnsure both vendors sign a Service Level Agreement (SLA) guaranteeing 99.9% uptime.
  4. DImplement end-to-end encryption for all data in transit and at rest between the two systems.
Show answer & explanation

Correct answer: D. Implement end-to-end encryption for all data in transit and at rest between the two systems.

Implementing end-to-end encryption ensures that data is protected from unauthorized access during transfer and storage, which is critical for meeting data privacy regulations when integrating systems from different vendors.

Why the other options are wrong

  • A. Daily backups address data recovery and availability, not the privacy of data during integration or storage.
  • B. A common identity provider addresses authentication and user experience, not the privacy of the data being exchanged.
  • C. An SLA for uptime addresses availability, not data privacy or compliance.

Data Privacy Compliance

Adhering to regulations and standards that protect personal and sensitive information from unauthorized access, use, or disclosure.

  • Often requires encryption, access controls, and data minimization.
  • Involves understanding and implementing legal frameworks like GDPR, HIPAA, CCPA.
  • Critical for maintaining trust and avoiding legal penalties.

Memory trick: Privacy Protects People's PII.

More Basics of IT and Governance questions