Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

An organization is architecting a hybrid cloud environment with AWS and on-premises resources. Which THREE considerations are essential for meeting data residency requirements? (Choose three.)

⚠ Common exam trap

CAS-005 often tests the nuances of data residency in hybrid cloud, and candidates may overlook the importance of encryption key location or think that on-premises storage is required, missing the essential considerations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Selecting the correct AWS region for data storage

Option A is correct because data residency is fundamentally about geography: choosing the correct AWS Region (e.g., eu-west-1 for EU data) ensures data at rest and in transit stays within the legally required jurisdiction, since AWS Regions are isolated geographic areas. Option C is correct because encryption keys are themselves regulated data; keeping KMS keys in the same Region as the encrypted data (or using a customer-managed KMS key in that Region) prevents cross-border key movement and satisfies residency controls such as those in GDPR or data-sovereignty mandates. Option D is correct because you cannot enforce residency without first knowing what data you hold; data classification policies identify regulated/sensitive data so it can be tagged, mapped, and placed only in approved Regions and on-premises locations. Option B is not required because hybrid architectures can store data in compliant AWS Regions, so mandating all-on-premises storage is overly restrictive and defeats the hybrid design. Option E is wrong because a global AWS account without Region constraints allows resources and data to be created in any Region, directly violating data residency requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Selecting the correct AWS region for data storage

    Why this is correct

    Data residency requires that stored data physically remains within a permitted jurisdiction. Choosing the correct AWS region determines the physical location of the data at rest, directly satisfying the legal constraint that data must not leave the approved territory.

  • ✗

    Using only on-premises storage for all data

    Why it's wrong here

    Restricting all data to on-premises storage abandons the hybrid design and prevents AWS services from processing regulated data. Keeping data on-premises is valid when residency mandates forbid any cross-border transfer, but the scenario requires hybrid placement with residency controls, not exclusion of cloud.

  • ✓

    Storing encryption keys in the same region as the data

    Why this is correct

    If encryption keys are held outside the data's jurisdiction, the data is effectively accessible from elsewhere and residency obligations can be breached. Co-locating keys in the same region as the data keeps the complete cryptographic boundary within the permitted territory.

  • ✓

    Implementing data classification policies

    Why this is correct

    Data classification identifies which datasets carry residency obligations and how they must be handled, directing where storage and processing may occur. Without classification, an organisation cannot reliably determine which data is subject to residency constraints, making compliant placement impossible.

  • ✗

    Using a global AWS account without region constraints

    Why it's wrong here

    A global AWS account without region constraints allows data to replicate or process in arbitrary regions, breaching residency mandates. Global accounts suit workloads with no geographic restrictions; residency requires explicit region selection, SCPs and service control policies pinning data to approved locations.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.