SY0-701 exam dumps

SY0-701 practice question 461 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 461

Single answer

A U.S.-based e-commerce company sells directly to customers in Germany, California, and Brazil. It uses a third-party cloud CRM provider to store customer profiles, support tickets, and marketing preferences. A customer in Germany submits a request to have personal data deleted. During the review, the security analyst finds the data exists in the production CRM, a marketing export on an internal file share, and a backup set retained for 7 years to meet financial recordkeeping requirements. Which action is the MOST appropriate for the company to take first to handle the request while reducing legal and privacy risk?

  1. A

    Delete all customer data from every location immediately, including backups, because the data subject's right to be forgotten overrides all retention requirements.

  2. B

    Determine whether the company is acting as the data controller, identify all repositories containing the subject's data through a data inventory, and evaluate which records must be deleted versus retained under applicable laws and retention obligations.

  3. C

    Direct the cloud CRM provider to process the deletion request because the provider stores the data and is therefore the data owner responsible for legal compliance.

  4. D

    Deny the request because the company is headquartered in the United States and is not subject to privacy laws created by other countries or regions.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to begin with governance and discovery: determine controller versus processor responsibilities, use a data inventory to identify all locations where the data subject's information resides, and then apply the correct retention and deletion rules. Under GDPR, the 'right to erasure' or 'right to be forgotten' applies in certain circumstances, but it is not unlimited; organizations may retain data when necessary to comply with legal obligations or for the establishment, exercise, or defense of legal claims. This makes data inventory and retention schedules critical controls. In this scenario, the company is likely the controller because it determines the purpose of collecting customer data for sales, support, and marketing, while the cloud CRM provider is the processor. A practical response includes validating the request, identifying all data stores, erasing unnecessary copies such as the internal marketing export if no lawful basis exists to keep it, coordinating processor actions, restricting or flagging data in backups as appropriate, and documenting any lawful retention exceptions. Relevant references include GDPR Articles 4 (definitions of controller and processor), 17 (right to erasure), and 30 (records of processing activities), as well as common privacy program best practices around data mapping, data minimization, and retention management.

  • A. Incorrect.

    This is incorrect because the right to be forgotten is not absolute. Privacy laws such as the GDPR include exceptions where data may need to be retained for compliance with legal obligations, such as tax, accounting, or other statutory retention requirements. In practice, organizations should remove data where required and feasible, but they also need to document lawful bases for retaining certain records. Backups may also require special handling rather than immediate deletion if deletion would impair integrity or violate retention controls.

  • B. Correct.

    This is correct because the company must first establish its role and obligations, then locate the data across systems using a data inventory. In this scenario, the company determines the purposes and means of processing customer data, so it is generally the data controller, while the cloud CRM provider is typically a processor acting on the controller's instructions. The right first step is to identify all copies of the subject's data, assess local/regional/global legal requirements, and distinguish data that should be erased from data that must be retained under valid retention schedules or legal obligations.

  • C. Incorrect.

    This is incorrect because storing the data does not automatically make the cloud CRM provider the data owner or controller. A common misconception is that the service hosting the data is legally responsible for deciding whether data should be deleted. In most business SaaS arrangements, the customer organization remains the controller because it decides why and how the data is processed, while the provider acts as a processor. The controller is responsible for responding to data subject requests and instructing processors accordingly.

  • D. Incorrect.

    This is incorrect because privacy obligations can apply based on where the data subjects are located, where goods or services are offered, and where processing occurs, not just where the company is headquartered. Selling to customers in Germany can trigger GDPR obligations, and operations involving California or Brazil may also raise CCPA/CPRA or LGPD considerations. Ignoring regional or national privacy laws because the company is U.S.-based creates significant legal and compliance risk.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam