Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A global enterprise is deploying a new application across multiple cloud regions to improve latency and resilience. Due to strict data residency regulations, certain types of sensitive customer data must remain within specific geographic boundaries. Which cloud security architecture principle is most relevant for ensuring compliance in this scenario?
- AContinuous security monitoring
- BDecentralized identity management
- CAutomated security orchestration
- DData locality and sovereignty
Show answer & explanationAnswer & explanation
Correct answer: D. Data locality and sovereignty
Data locality and sovereignty directly address the requirement for data to reside and be governed by the laws of a specific geographic region, which is critical for meeting data residency regulations.
Why the other options are wrong
- A. Continuous monitoring helps detect issues but doesn't ensure data is stored in the correct region.
- B. Decentralized identity management focuses on user identity, not data residency.
- C. Automated orchestration helps manage security tasks but doesn't define data placement.
Data Locality and Sovereignty
Principles that dictate where data must be stored (locality) and which legal jurisdiction's laws apply to that data (sovereignty), often driven by regulatory requirements.
- Ensures compliance with data residency laws.
- Impacts cloud region selection and data architecture.
- Crucial for global businesses handling sensitive data.
Memory trick: Cloud data must follow its country's rules and stay in its place.