CAS-004 Security Architecture Practice Question
A global company must comply with data residency regulations that require customer data to stay within specific geographic boundaries. The company uses a multi-cloud architecture. Which THREE strategies should the architect implement to ensure compliance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using cloud provider's region-specific services and data centers
To meet data residency requirements, data must be stored and processed locally. Encryption alone does not prevent data from leaving the region. Private links keep traffic within the cloud provider's network but do not guarantee data stays in region. Access controls do not prevent data movement. Data classification helps identify regulated data. Cloud provider's region-specific services ensure data remains in that region.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using cloud provider's region-specific services and data centers
Why this is correct
Choosing specific regions ensures data is stored and processed within the desired geography.
- ✗
Encrypting all data at rest and in transit
Why it's wrong here
Encryption protects confidentiality but does not enforce geographic boundaries; data can still be moved.
- ✗
Implementing strict identity and access management (IAM) policies
Why it's wrong here
IAM controls access but does not prevent authorized users from moving data across regions.
- ✓
Configuring data classification tags to identify regulated data
Why this is correct
Data classification enables automated enforcement of residency policies based on data sensitivity.
- ✓
Deploying data loss prevention (DLP) policies to block cross-border data transfers
Why this is correct
DLP policies can monitor and prevent data from being transferred out of approved regions.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.