SY0-701 exam dumps

SY0-701 practice question 412 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 412

Select 3External considerations: Regulatory , Legal , Industry , Local/regional , National , Global

A U.S.-based e-commerce company is expanding into the European Union and Brazil. The company collects customer names, email addresses, shipping addresses, and payment card data through its website. During a security planning meeting, the security analyst is asked to identify which external considerations must directly influence the company's data handling and incident response requirements before launch. Which of the following should the analyst prioritize?

  1. A

    Compliance with GDPR for EU customer personal data and LGPD for Brazilian customer personal data

  2. B

    Alignment with PCI DSS requirements for processing, transmitting, and storing payment card data

  3. C

    Replacement of all company security policies with the cyber laws of the country where the headquarters is located

  4. D

    Use of only U.S. state breach notification timelines for all incidents worldwide

  5. E

    Review of local and national breach notification and privacy requirements in each jurisdiction where customers are located

Show answer and explanation

Correct answers: A, B, E

Explanation

The best answers are 1, 2, and 5 because the scenario involves multiple categories of external considerations: regulatory/legal requirements such as GDPR and LGPD, industry obligations such as PCI DSS, and local/regional/national breach notification rules. Security+ expects candidates to recognize that security programs are shaped not just by internal policy but also by external obligations that vary by jurisdiction and industry. GDPR is an EU regulation governing personal data processing, while Brazil's LGPD is a national privacy law with similar concepts around personal data protection. PCI DSS is a widely recognized industry security standard required for organizations that handle payment card data. In addition, breach notification and privacy obligations may differ across states, countries, and regions, so incident response plans must be adapted accordingly. These concepts align with common security governance best practices and published requirements from the European Data Protection Board for GDPR-related guidance, the Brazilian data protection authority for LGPD, and the PCI Security Standards Council for PCI DSS.

  • A. Correct.

    This is correct. GDPR applies to the processing of personal data of individuals in the EU, and Brazil's LGPD applies to personal data processed in Brazil. Because the company is expanding operations into those markets and collecting customer personal information, these regulatory and legal requirements are direct external considerations. They can affect lawful processing, privacy notices, data subject rights, cross-border transfers, and incident reporting obligations.

  • B. Correct.

    This is correct. PCI DSS is an industry requirement that applies when an organization stores, processes, or transmits payment card data. Even though PCI DSS is not a government law in most jurisdictions, it is still a major external consideration because card brands and acquiring banks require it contractually. For a company handling payment card data, it directly affects technical controls, segmentation, logging, vulnerability management, and incident response procedures.

  • C. Incorrect.

    This is incorrect. Organizations do not replace all internal security policies with the laws of the headquarters location. A multinational company must account for multiple external obligations, including regional laws, national regulations, and industry requirements. Internal policies should be updated to align with applicable legal and regulatory obligations across all relevant jurisdictions, not limited to headquarters.

  • D. Incorrect.

    This is incorrect. Using only U.S. state breach notification timelines for all incidents worldwide ignores legal and regulatory differences across countries and regions. Different jurisdictions may impose different thresholds, reporting timelines, and notification recipients. For example, some privacy frameworks require notification to regulators within defined timeframes that differ from U.S. state laws.

  • E. Correct.

    This is correct. Local, regional, and national requirements can differ significantly and must be reviewed wherever the organization operates or where affected individuals reside. Breach notification obligations may vary by country, state, or region, including who must be notified, when notification is required, and what details must be included. This is a core example of external legal and regulatory considerations affecting security operations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam