Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

A multinational retailer operates an on-premises data center and two public cloud regions. Regulations require that customer payment data never leave the home country, but the company wants centralized security analytics. The architect needs a design that keeps raw payment records local while enabling global threat detection. Which design best meets these constraints?

⚠ Common exam trap

The trap here is believing that encryption or tokenization automatically resolves data residency, when regulations govern where the records are stored and processed regardless of their encryption state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Keep raw payment records in the home country and forward only normalized security telemetry to a central SIEM.

Local retention of raw payment records meets the residency regulation, while exporting only normalized security telemetry to a central SIEM preserves the global correlation needed for threat detection. This separates regulated data from operational telemetry. Full replication, per-region silos, and encrypted offsite storage each either move regulated records across borders or prevent the centralized analytics the company requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Keep raw payment records in the home country and forward only normalized security telemetry to a central SIEM.

    Why this is correct

    Keeping raw payment records local satisfies data residency, while forwarding normalized telemetry such as authentication events, network flows, and alerts gives the central SIEM the visibility needed for global threat detection. The telemetry is stripped of payment data, so no regulated records cross borders, and correlation across regions remains possible for detecting coordinated attacks.

  • ✗

    Replicate the full payment database to a central cloud data lake for analytics.

    Why it's wrong here

    Replicating full payment records to a central data lake violates the data residency requirement because raw payment data would leave the home country. Even with encryption, the records themselves cross the border, which regulators prohibit. The design must keep raw records local while still enabling analytics, so full replication is disqualified regardless of the analytics benefits.

  • ✗

    Deploy independent SIEM instances per region with no cross-region data sharing.

    Why it's wrong here

    Fully isolated SIEM instances satisfy residency but defeat the goal of centralized global threat detection. Attacks that span regions, such as a credential stuffing campaign hitting multiple storefronts, would appear as unrelated local events. The architect needs a way to correlate across regions without moving raw payment data, which this design does not provide.

  • ✗

    Encrypt payment records with a customer-managed key and store them in the nearest cloud region.

    Why it's wrong here

    Encryption protects confidentiality but does not change where the data resides. Storing records in the nearest cloud region may place them outside the home country, violating the residency regulation even though the ciphertext is unreadable to the provider. The requirement is about location of the records, not their protection state.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.