Courseiva
mediumMultiple SelectObjective-mapped

CAS-004 Data Residency Practice Question

A security architect is designing a cloud-native application that must comply with GDPR data residency requirements. Which TWO of the following measures should the architect implement? (Choose two.)

⚠ Common exam trap

Candidates may incorrectly assume that encryption (Option D) satisfies data residency because it is a commonly cited GDPR requirement. However, residency specifically concerns the geographical location of data storage, which encryption does not address. The correct complementary controls for residency are restricting storage locations (B) and monitoring data transfers (C).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Store data only in approved geographical locations

GDPR requires that personal data of EU residents be stored within the EEA or in jurisdictions with an adequacy decision, making geographical storage restrictions a direct residency measure. Option C is also correct because data loss prevention (DLP) policies can monitor and block unauthorized data transfers out of approved regions, enforcing compliance with data residency requirements. Option D is incorrect; while encryption is a security measure required under GDPR Article 32, it does not ensure that data stays within approved geographical boundaries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy the application in a single region to simplify compliance

    Why it's wrong here

    Deploying in a single region does not guarantee compliance if that region is not approved; it also introduces availability risks.

  • Store data only in approved geographical locations

    Why this is correct

    Correct. Storing data only in approved geographical locations directly addresses GDPR data residency by ensuring data remains within the EEA or equivalent.

  • Use data loss prevention (DLP) policies to monitor data transfers

    Why this is correct

    Correct. DLP policies can detect and prevent data egress to unapproved locations, supporting residency enforcement.

  • Encrypt data at rest and in transit

    Why it's wrong here

    Incorrect. Encryption secures data but does not control where data is stored; residency is about location, not protection.

  • Implement data classification and labeling

    Why it's wrong here

    Data classification helps identify personal data but does not enforce geographical storage restrictions.

About these practice questions

One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.