mediumMultiple Choice
CAS-004 Practice Question: Is migrating sensitive customer data to a public…
An organization is migrating sensitive customer data to a public cloud. Which of the following actions best demonstrates due diligence for compliance with GDPR?
⚠ Common exam trap
CompTIA often tests the distinction between operational security controls (like encryption) or contractual safeguards (like DPAs) and the procedural due diligence required by GDPR, leading candidates to pick a technically valid but compliance-incomplete answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting a data protection impact assessment (DPIA).
A Data Protection Impact Assessment (DPIA) is a mandatory requirement under GDPR Article 35 for processing activities that are likely to result in high risk to individuals' rights and freedoms, such as migrating sensitive customer data to a public cloud. Conducting a DPIA demonstrates due diligence by systematically identifying, assessing, and mitigating privacy risks before the migration begins, ensuring compliance with GDPR's accountability principle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conducting a data protection impact assessment (DPIA).
Why this is correct
A DPIA directly satisfies GDPR Article 35, which mandates assessing high-risk processing before migrating sensitive customer data. It systematically identifies privacy risks, documents lawful basis and mitigation, and evidences accountability to supervisory authorities. This proactive, documented evaluation demonstrates due diligence more concretely than reactive or purely contractual measures.
- ✗
Enabling server-side encryption on the cloud storage.
Why it's wrong here
Server-side encryption protects data at rest but does not by itself demonstrate GDPR accountability or lawful processing; a DPA is the required contractual instrument. Encryption is tempting as a security control, yet it addresses confidentiality, not the controller-processor obligations GDPR imposes.
- ✗
Obtaining explicit consent from all data subjects.
Why it's wrong here
Consent is one of several lawful bases under GDPR Article 6, not a universal due-diligence action for a migration; processing may instead rely on contract or legitimate interest. It is tempting because consent is well known, but it addresses lawfulness, not the accountability evidence a migration review requires.
- ✗
Signing a data processing agreement (DPA) with the cloud provider.
Why it's wrong here
A DPA is a contractual requirement under GDPR Article 28, but due diligence for a migration is demonstrated by assessing the provider's safeguards, not merely signing paperwork. It is tempting because DPAs are mandatory, yet they document obligations rather than evidence the technical and organisational measures themselves.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.