100-160 Question 206
Select 3An organization is implementing a new cloud-based customer relationship management (CRM) system. During the security assessment, the IT team discovers that sensitive customer data, including personally identifiable information (PII), will be processed and stored in the system. Which of the following actions should be prioritized to ensure proper data classification and protection?
- A
Classify the customer data according to its sensitivity and regulatory requirements.
- B
Implement strong access controls to ensure only authorized personnel can access the data.
- C
Focus solely on encrypting the data in transit, as encryption at rest is unnecessary for PII.
- D
Ensure the CRM vendor complies with relevant data protection regulations, such as GDPR or CCPA.
- E
Perform regular penetration testing to identify potential vulnerabilities in the CRM system.
Show answer and explanation
Correct answers: A, B, D
Explanation
To protect sensitive customer data such as PII, organizations must classify the data, implement access controls, and ensure compliance with relevant regulations. These actions directly address the risks associated with storing and processing sensitive data in a third-party system like a CRM. While encryption and penetration testing are important, they are not the primary focus for data classification and protection in this context.
- A. Correct.
Classifying the data ensures that the organization understands its sensitivity and any regulatory requirements, which is essential for proper handling and protection.
- B. Correct.
Implementing access controls is critical to protect sensitive customer data by limiting access to authorized personnel only.
- C. Incorrect.
While encrypting data in transit is important, encrypting data at rest is also crucial for protecting PII. This option is incorrect because it dismisses the need for encryption at rest.
- D. Correct.
Ensuring vendor compliance with regulations is critical to protect customer data and avoid legal or financial repercussions.
- E. Incorrect.
While penetration testing is an important security measure, it is not directly related to data classification or ensuring compliance and protection in this scenario.