mediumMultiple SelectObjective-mapped
CAS-004 Data Residency Practice Question
A security architect is designing a cloud-native application that must comply with GDPR data residency requirements. Which TWO of the following measures should the architect implement? (Choose two.)
⚠ Common exam trap
Candidates may incorrectly assume that encryption (Option D) satisfies data residency because it is a commonly cited GDPR requirement. However, residency specifically concerns the geographical location of data storage, which encryption does not address. The correct complementary controls for residency are restricting storage locations (B) and monitoring data transfers (C).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store data only in approved geographical locations
GDPR requires that personal data of EU residents be stored within the EEA or in jurisdictions with an adequacy decision, making geographical storage restrictions a direct residency measure. Option C is also correct because data loss prevention (DLP) policies can monitor and block unauthorized data transfers out of approved regions, enforcing compliance with data residency requirements. Option D is incorrect; while encryption is a security measure required under GDPR Article 32, it does not ensure that data stays within approved geographical boundaries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the application in a single region to simplify compliance
Why it's wrong here
Deploying in a single region does not guarantee compliance if that region is not approved; it also introduces availability risks.
- ✓
Store data only in approved geographical locations
Why this is correct
Correct. Storing data only in approved geographical locations directly addresses GDPR data residency by ensuring data remains within the EEA or equivalent.
- ✓
Use data loss prevention (DLP) policies to monitor data transfers
Why this is correct
Correct. DLP policies can detect and prevent data egress to unapproved locations, supporting residency enforcement.
- ✗
Encrypt data at rest and in transit
Why it's wrong here
Incorrect. Encryption secures data but does not control where data is stored; residency is about location, not protection.
- ✗
Implement data classification and labeling
Why it's wrong here
Data classification helps identify personal data but does not enforce geographical storage restrictions.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.