Courseiva
mediumMultiple ChoiceObjective-mapped

CAS-004 Practice Question: Is migrating sensitive customer data to a public…

An organization is migrating sensitive customer data to a public cloud. Which of the following actions best demonstrates due diligence for compliance with GDPR?

⚠ Common exam trap

CompTIA often tests the distinction between operational security controls (like encryption) or contractual safeguards (like DPAs) and the procedural due diligence required by GDPR, leading candidates to pick a technically valid but compliance-incomplete answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conducting a data protection impact assessment (DPIA).

A Data Protection Impact Assessment (DPIA) is a mandatory requirement under GDPR Article 35 for processing activities that are likely to result in high risk to individuals' rights and freedoms, such as migrating sensitive customer data to a public cloud. Conducting a DPIA demonstrates due diligence by systematically identifying, assessing, and mitigating privacy risks before the migration begins, ensuring compliance with GDPR's accountability principle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conducting a data protection impact assessment (DPIA).

    Why this is correct

    A DPIA is mandated by GDPR for high-risk processing and demonstrates thorough due diligence.

  • Enabling server-side encryption on the cloud storage.

    Why it's wrong here

    Encryption is a technical control but does not constitute due diligence regarding compliance.

  • Obtaining explicit consent from all data subjects.

    Why it's wrong here

    Consent is one legal basis but does not replace the need for a DPIA.

  • Signing a data processing agreement (DPA) with the cloud provider.

    Why it's wrong here

    While a DPA is required, due diligence involves assessing risks before migration.

About these practice questions

This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.