N10-009 exam dumps

N10-009 practice question 258 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 258

Single answer

A retail company based in Germany is migrating its e-commerce platform to a cloud provider. The environment will process credit card payments for EU customers and store customer account information, including names, addresses, and order history. During a pre-deployment audit, the network administrator learns that the proposed design replicates the payment application database to a backup region in the United States and places the cardholder data environment on the same VLAN as the internal corporate user network. Which action should the administrator take FIRST to best address the most immediate compliance issues related to GDPR, PCI DSS, and data locality?

  1. A

    Redesign the network to segment the cardholder data environment from the corporate network and verify that EU personal data replication to the U.S. has an approved lawful transfer mechanism or is restricted to an EU region

  2. B

    Enable port security on all access switches and document the MAC addresses of payment servers for the audit

  3. C

    Increase Internet bandwidth to the U.S. backup region so encrypted database replication completes faster during peak sales periods

  4. D

    Replace the stateful firewall with a next-generation firewall so the environment automatically becomes PCI DSS compliant

Show answer and explanation

Correct answer: A

Explanation

The best answer is to address both the network architecture and the data transfer design. For PCI DSS, isolating the cardholder data environment from the general corporate network is a key best practice that reduces scope and limits access paths to systems handling account data. PCI DSS documentation emphasizes restricting connections to cardholder data and using network segmentation to reduce exposure, even though segmentation is not explicitly mandated in every case. For GDPR, personal data of EU residents transferred outside the European Economic Area must have an appropriate lawful transfer mechanism and safeguards. Replicating customer data from Germany to a U.S. region raises a cross-border transfer issue that must be validated during design, not after deployment. Data locality requirements may also come from internal policy, contract terms, or sector-specific obligations, so restricting storage and backup to EU regions may be necessary. In an audit context, the first priority is to correct the design elements that create immediate compliance risk: improper CDE placement and potentially unlawful data transfer.

  • A. Correct.

    Correct. This option addresses the two clearest compliance risks in the scenario. PCI DSS requires organizations to protect cardholder data and strongly emphasizes network segmentation to reduce exposure of the cardholder data environment (CDE). Placing the CDE on the same VLAN as the corporate user network increases scope and risk. GDPR and data locality concerns are also implicated because EU personal data is being replicated to the U.S.; this cross-border transfer must have a valid legal basis and appropriate safeguards, or the data should remain within approved EU locations. This is the most appropriate first action because it directly targets the identified audit findings.

  • B. Incorrect.

    Incorrect. Port security may be a useful switch hardening control, but it does not resolve the major compliance issues described. It does not address improper CDE segmentation under PCI DSS, nor does it address the legality of transferring EU personal data to a U.S. region under GDPR and data transfer rules. This option reflects a common mistake of focusing on a technical control that is too narrow for the compliance problem presented.

  • C. Incorrect.

    Incorrect. Faster replication does not address whether replication to the U.S. is legally permissible under GDPR or whether the CDE is properly isolated for PCI DSS purposes. Encryption and performance improvements can be helpful operationally, but increasing bandwidth does not remediate the audit concerns. This is a plausible distractor because administrators often think in terms of improving technical performance rather than reducing compliance risk.

  • D. Incorrect.

    Incorrect. A next-generation firewall can improve visibility and policy enforcement, but deploying one does not automatically make an environment PCI DSS compliant. Compliance depends on architecture, segmentation, access control, monitoring, documentation, and many other requirements. It also does not by itself solve GDPR data transfer or data locality issues. This option tests the misconception that buying a security product is equivalent to achieving compliance.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam