N10-009 exam dumps

N10-009 practice question 257 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 257

Select 2

A retail company based in Germany is migrating its e-commerce platform to a public cloud provider. The platform processes customer card payments and stores customer account data for EU residents. During a pre-audit review, the security team discovers that cardholder data backups are replicated to a data center in another region outside the EU, and the current design allows administrators to manage the cardholder data environment from the general corporate network. The company must reduce compliance risk before going live. Which TWO actions should the network team recommend?

  1. A

    Restrict storage and replication of EU customer personal data to approved geographic regions, and verify the provider's regional data residency controls

  2. B

    Segment the cardholder data environment from the corporate network with tightly controlled access paths and firewall rules

  3. C

    Allow global backup replication to continue because encrypted data is exempt from data locality and GDPR considerations

  4. D

    Move all payment processing traffic onto the guest wireless network to isolate it from the internal LAN

  5. E

    Rely on the cloud provider's standard terms alone, since PCI DSS and GDPR compliance transfer fully to the provider in a managed service model

Show answer and explanation

Correct answers: A, B

Explanation

The best answers are to enforce approved regional data residency for EU personal data and to segment the cardholder data environment from the rest of the enterprise network. GDPR places obligations on organizations handling EU personal data, including restrictions and safeguards for transfers outside the EU/EEA. Data locality decisions therefore matter during cloud design. PCI DSS requires organizations to protect cardholder data through strong network security controls, including restricting access to the CDE, managing inbound and outbound traffic, and minimizing exposure through segmentation and controlled administration. Relevant guidance includes the PCI DSS requirements for network security controls and access restriction, as well as GDPR rules on processing and international data transfers. In practice, auditors expect to see documented region selection, controlled replication, restricted administrative paths, firewall rules, and clear separation between the CDE and less-trusted networks.

  • A. Correct.

    Correct. This addresses data locality and GDPR-related concerns. If the company stores or replicates EU residents' personal data outside approved regions, it must ensure lawful transfer mechanisms and appropriate controls. From a network and architecture standpoint, selecting approved storage regions and preventing unapproved replication helps reduce compliance risk. This is especially important when audit findings show data is being copied to a non-EU region without clear justification or safeguards.

  • B. Correct.

    Correct. PCI DSS requires network segmentation and strong access control around the cardholder data environment (CDE). While segmentation is not mandated in every wording as a single control, it is a widely accepted best practice that reduces scope and risk. Separating the CDE from the corporate network and limiting administrative access through controlled paths, ACLs, and firewalls directly addresses the finding that administrators can currently reach the environment from the general network.

  • C. Incorrect.

    Incorrect. Encryption does not automatically remove data locality or GDPR obligations. Personal data remains regulated even when encrypted, and cross-border transfers can still require appropriate legal and technical safeguards. This option reflects the common misconception that encryption alone makes location irrelevant for compliance.

  • D. Incorrect.

    Incorrect. Guest wireless networks are typically designed for untrusted or internet-only access and are not appropriate for payment processing traffic. PCI DSS environments require secured, controlled, and monitored network segments, not placement on a guest VLAN or SSID. Someone might choose this option because it sounds like isolation, but it is the wrong type of isolation.

  • E. Incorrect.

    Incorrect. Compliance responsibility does not fully transfer to the cloud provider. Under shared responsibility models, the provider may secure underlying infrastructure, but the customer remains responsible for many configuration, access, segmentation, and data handling controls. PCI DSS scoping and GDPR obligations still apply to the organization using the service.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam