SY0-701 exam dumps

SY0-701 practice question 411 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 411

Single answerExternal considerations: Regulatory , Legal , Industry , Local/regional , National , Global

A U.S.-based e-commerce company is expanding into the European Union and Brazil. The company processes online payments, stores customer account data, and uses a third-party cloud provider to host its customer portal. During a security planning meeting, the security manager is asked which external consideration should be addressed first to reduce the risk of noncompliance fines and legal exposure before launch. Which of the following is the BEST answer?

  1. A

    Review applicable privacy and breach-notification laws for each region where customer data is collected or processed, and map technical controls to those requirements

  2. B

    Adopt a single internal security standard and apply it globally so regional differences do not create administrative overhead

  3. C

    Prioritize only the cloud provider's shared responsibility model because legal obligations transfer to the hosting provider once data is outsourced

  4. D

    Focus on U.S. federal cybersecurity guidance first, because national requirements automatically satisfy industry and international obligations

Show answer and explanation

Correct answer: A

Explanation

The best answer is to first identify and assess the legal and regulatory obligations that apply across all relevant jurisdictions and then map security controls to those requirements. In this scenario, the company faces multiple external considerations at once: legal and regulatory requirements tied to the EU and Brazil, industry obligations related to payment card processing, and contractual or operational responsibilities connected to the cloud provider. A Security+ candidate should recognize that external considerations are not limited to technical standards; they also include regulatory, legal, industry, local/regional, national, and global requirements.

Relevant references include the EU General Data Protection Regulation (GDPR), Brazil's Lei Geral de Protecao de Dados (LGPD), and the PCI DSS from the PCI Security Standards Council. In practice, organizations commonly perform a compliance applicability assessment, data flow mapping, and control mapping exercise before launching in new regions. This helps determine which privacy notices, contractual clauses, access controls, logging, encryption practices, and breach notification processes are required. The key exam concept is that organizations must account for the most specific applicable external obligations rather than assuming a single policy, provider, or national standard covers all environments.

  • A. Correct.

    Correct. When operating across multiple jurisdictions, the organization must first identify the regulatory and legal requirements that apply where data subjects reside and where data is processed. For EU customers, privacy obligations under the GDPR are a major consideration, including lawful basis, data subject rights, and breach notification requirements. For Brazil, the LGPD imposes similar privacy obligations. Because the company also processes payment cards, PCI DSS is an important industry requirement, but legal and regulatory exposure from privacy laws can create immediate compliance and contractual risks if not identified early. Mapping controls to jurisdiction-specific requirements is the most effective first step.

  • B. Incorrect.

    Incorrect. A single global internal standard can be useful as a baseline, but it does not replace compliance with local, regional, or national requirements. Different jurisdictions may have unique breach reporting timelines, data residency expectations, cross-border transfer restrictions, or consent requirements. Assuming one internal standard is enough is a common mistake and can leave the company noncompliant.

  • C. Incorrect.

    Incorrect. The shared responsibility model does not transfer all legal or regulatory obligations to the cloud provider. The provider may secure parts of the infrastructure, but the customer typically remains responsible for data classification, access control, privacy compliance, configuration, and incident response obligations. Outsourcing hosting does not outsource accountability for compliance.

  • D. Incorrect.

    Incorrect. U.S. federal guidance may help improve security posture, but it does not automatically satisfy other external considerations such as GDPR, LGPD, or PCI DSS. National guidance from one country is not a substitute for regional laws, industry frameworks, or international obligations. This option reflects a misunderstanding that security best practices alone equal compliance.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam