CAS-004 Governance, Risk, and Compliance Practice Question
A multinational financial services firm is expanding operations into a new jurisdiction. The legal team has identified that the new country requires all personal data of its citizens to be stored on servers physically located within its borders. The security architect must recommend an approach that satisfies this requirement while maintaining the firm's global security standards. Which of the following should the architect recommend?
⚠ Common exam trap
The trap here is assuming that encryption or tokenization eliminates the need for physical data residency, when the law explicitly requires data to be stored within the jurisdiction's borders.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement data localization by deploying dedicated infrastructure in the new jurisdiction and applying the firm's global security baselines to those systems.
Data localization laws require that personal data of a jurisdiction's citizens be stored on physical servers within that jurisdiction. Deploying dedicated in-country infrastructure and applying the organization's global security baselines directly satisfies this legal requirement while ensuring consistent security controls. Other options either store data outside the jurisdiction or fail to guarantee in-country residency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement tokenization so that only non-sensitive tokens are stored in the new jurisdiction while actual data remains in the central repository.
Why it's wrong here
Tokenization replaces sensitive data with non-sensitive placeholders, but the actual personal data would still reside outside the jurisdiction. The law mandates that the personal data itself be stored locally. Tokenization may reduce scope for other compliance regimes, but it does not fulfill the data residency requirement in this scenario.
- ✗
Use a content delivery network (CDN) to cache personal data at edge locations closest to the new jurisdiction's users.
Why it's wrong here
A CDN caches content globally to improve performance, but it does not guarantee that data remains within a specific country's borders. Edge locations are distributed across many regions, so personal data could be stored or processed outside the required jurisdiction. This approach fails to meet the legal mandate for strict data residency and could result in regulatory penalties.
- ✗
Encrypt all personal data with customer-managed keys and store it in the firm's existing central data center.
Why it's wrong here
Encryption protects data confidentiality but does not change its physical location. The jurisdiction's law requires data to be stored on servers within its borders, regardless of encryption. Storing encrypted data in a central data center outside the country violates the localization requirement and does not satisfy the legal obligation.
- ✓
Implement data localization by deploying dedicated infrastructure in the new jurisdiction and applying the firm's global security baselines to those systems.
Why this is correct
Data localization laws require data to remain within the jurisdiction's borders. Deploying dedicated in-country infrastructure and enforcing the firm's global security baselines satisfies the legal requirement without compromising security consistency. This approach directly addresses the sovereignty mandate while allowing the organization to maintain its standard controls, monitoring, and hardening practices across all environments.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.