CAS-004 Security Architecture Practice Question
An organization is architecting a hybrid cloud environment with AWS and on-premises resources. Which THREE considerations are essential for meeting data residency requirements? (Choose three.)
⚠ Common exam trap
CAS-005 often tests the nuances of data residency in hybrid cloud, and candidates may overlook the importance of encryption key location or think that on-premises storage is required, missing the essential considerations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Selecting the correct AWS region for data storage
Option A is correct because data residency is fundamentally about geography: choosing the correct AWS Region (e.g., eu-west-1 for EU data) ensures data at rest and in transit stays within the legally required jurisdiction, since AWS Regions are isolated geographic areas. Option C is correct because encryption keys are themselves regulated data; keeping KMS keys in the same Region as the encrypted data (or using a customer-managed KMS key in that Region) prevents cross-border key movement and satisfies residency controls such as those in GDPR or data-sovereignty mandates. Option D is correct because you cannot enforce residency without first knowing what data you hold; data classification policies identify regulated/sensitive data so it can be tagged, mapped, and placed only in approved Regions and on-premises locations. Option B is not required because hybrid architectures can store data in compliant AWS Regions, so mandating all-on-premises storage is overly restrictive and defeats the hybrid design. Option E is wrong because a global AWS account without Region constraints allows resources and data to be created in any Region, directly violating data residency requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Selecting the correct AWS region for data storage
Why this is correct
Data residency requires that stored data physically remains within a permitted jurisdiction. Choosing the correct AWS region determines the physical location of the data at rest, directly satisfying the legal constraint that data must not leave the approved territory.
- ✗
Using only on-premises storage for all data
Why it's wrong here
Restricting all data to on-premises storage abandons the hybrid design and prevents AWS services from processing regulated data. Keeping data on-premises is valid when residency mandates forbid any cross-border transfer, but the scenario requires hybrid placement with residency controls, not exclusion of cloud.
- ✓
Storing encryption keys in the same region as the data
Why this is correct
If encryption keys are held outside the data's jurisdiction, the data is effectively accessible from elsewhere and residency obligations can be breached. Co-locating keys in the same region as the data keeps the complete cryptographic boundary within the permitted territory.
- ✓
Implementing data classification policies
Why this is correct
Data classification identifies which datasets carry residency obligations and how they must be handled, directing where storage and processing may occur. Without classification, an organisation cannot reliably determine which data is subject to residency constraints, making compliant placement impossible.
- ✗
Using a global AWS account without region constraints
Why it's wrong here
A global AWS account without region constraints allows data to replicate or process in arbitrary regions, breaching residency mandates. Global accounts suit workloads with no geographic restrictions; residency requires explicit region selection, SCPs and service control policies pinning data to approved locations.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.