PK0-005 Practice Question: Basics of IT Infrastructure and IT Project Management
A project team is evaluating cloud providers for a SaaS application. The provider must guarantee 99.99% uptime and support data sovereignty requirements. Which service level agreement (SLA) clause is most critical to review?
⚠ Common exam trap
The PK0-005 exam often tests the distinction between security controls (encryption) and legal/regulatory compliance (data residency), leading candidates to mistakenly choose encryption standards when the core requirement is geographic data control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data residency and location clauses
The question explicitly requires the provider to support data sovereignty, which mandates that data must be stored and processed within specific geographic boundaries. The SLA clause on data residency and location clauses (Option D) directly addresses this by defining where data centers are located and whether data can be moved across borders. Without this clause, the provider could store data in jurisdictions violating legal or regulatory requirements, making it the most critical clause to review.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data encryption standards
Why it's wrong here
Encryption standards protect data confidentiality in transit and at rest, but they do not guarantee 99.99% uptime or dictate where data is physically stored. It is tempting because encryption supports compliance, yet data sovereignty concerns jurisdiction and residency, which the availability and sovereignty clause must specify.
- ✗
Financial penalty for downtime
Why it's wrong here
A financial penalty clause specifies compensation when availability targets are missed; it does not itself define the uptime guarantee or address where data is stored. It is tempting because penalties enforce commitments, but the critical clause must state the 99.99% availability level and data sovereignty obligations.
- ✗
Incident response and escalation procedure
Why it's wrong here
Incident response and escalation procedures define how outages are reported and resolved, not the guaranteed availability percentage or the geographic location of data. It is tempting because escalation supports uptime, but the scenario's requirements are met by the availability commitment and data sovereignty clause.
- ✓
Data residency and location clauses
Why this is correct
Data residency and location clauses define where the provider stores and processes data, directly satisfying the sovereignty requirement. Uptime guarantees address availability, not jurisdiction, so residency clauses are the critical term to verify for regulatory compliance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PK0-005 question from scratch — 954 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.