CompTIA Security+ (SY0-501) — Question 421

The Chief Security Officer (CISO) at a multinational banking corporation is reviewing a plan to upgrade the entire corporate IT infrastructure. The architecture consists of a centralized cloud environment hosting the majority of data, small server clusters at each corporate location to handle the majority of customer transaction processing, ATMs, and a new mobile banking application accessible from smartphones, tablets, and the Internet via HTTP. The corporation does business having varying data retention and privacy laws.
Which of the following technical modifications to the architecture and corresponding security controls should be implemented to provide the MOST complete protection of data?

Answer options

Correct answer: C

Explanation

Option C is correct because it addresses the need to comply with varying data retention and privacy laws by storing data based on national borders and ensuring end-to-end encryption. Other options, while they include important security measures like encryption, do not fully consider the legal implications of data jurisdiction, which is critical for compliance in a multinational context.