Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard

A global automotive manufacturer is developing highly connected autonomous vehicles. These vehicles generate vast amounts of telemetry data, including sensitive location data, driving patterns, and biometric information, which must comply with various regional privacy regulations (e.g., GDPR, CCPA). The cybersecurity architect needs to implement a GRC technical strategy that ensures privacy-by-design for data generated by vehicles, automatically redacting or anonymizing sensitive information before it leaves the vehicle or is stored in backend systems, while still allowing for necessary analytics. Which strategy is MOST appropriate?

  1. AImplementing a centralized data lake for all raw telemetry data with post-processing anonymization.
  2. BDeploying a robust Data Loss Prevention (DLP) solution at the cloud ingress points.
  3. CUtilizing edge computing and anonymization techniques within the vehicle's processing unit before data transmission.
  4. DEstablishing a comprehensive legal framework for data sharing agreements with data consumers.
Show answer & explanation

Correct answer: C. Utilizing edge computing and anonymization techniques within the vehicle's processing unit before data transmission.

Edge computing within the vehicle allows for immediate processing and anonymization/redaction of sensitive data at the source (privacy-by-design). This ensures that privacy regulations are met before the data is transmitted, minimizing the risk of sensitive data exposure in transit or storage, while still enabling valuable analytics on the anonymized dataset.

Why the other options are wrong

  • A. A centralized data lake with post-processing means sensitive data is collected and stored before anonymization, violating privacy-by-design principles and increasing compliance risk, especially for real-time data.
  • B. DLP at cloud ingress points only protects data once it reaches the cloud, not at the source (the vehicle), which is too late for 'privacy-by-design' and may not prevent sensitive data from being transmitted initially.
  • D. A legal framework is crucial for GRC but is a contractual control, not a technical strategy for automatic, real-time data anonymization at the source within the vehicle's operational flow.

Edge Anonymization for IoT/Vehicles

Processing and anonymizing sensitive data directly at the data source (e.g., within a vehicle or IoT device) using edge computing, ensuring privacy-by-design before data leaves the local environment.

  • Implements privacy-by-design at the source.
  • Reduces sensitive data exposure during transmission and storage.
  • Enables compliance with privacy regulations for real-time data.

Memory trick: Vehicle data privacy starts at the edge, anonymize before it speeds away.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions