Soru

Zorluk: ZorData Privacy and Compliance Regulations

An IT support technician is configuring a local backup script on a workstation used by a financial services firm's human resources department. The workstation stores records containing national identification numbers, home addresses, and bank details of European Union residents. The department manager asks the technician to ensure the backup workflow complies with General Data Protection Regulation (GDPR) requirements for protecting this personally identifiable information (PII). Which of the following technical controls should the technician implement to meet GDPR compliance standards?

  1. Apply strong cryptographic encryption to the backups at rest and in transit while enforcing least privilege access controls.Cevap
  2. B
    Isolate the workstation on a separate VLAN that allows cleartext data transmission locally while blocking external internet access.
  3. C
    Anonymize the backup transaction logs while retaining national identification numbers in plaintext to simplify compliance auditing.
  4. D
    Perform daily physical degaussing of the workstation's local primary storage drive after every completed backup cycle.

Cevap

Apply strong cryptographic encryption to the backups at rest and in transit while enforcing least privilege access controls.
Under General Data Protection Regulation (GDPR) guidelines, organizations handling personally identifiable information (PII) of EU citizens must implement appropriate technical security measures. Applying end-to-end encryption for data both at rest (stored backups) and in transit (network transfers), combined with access restricted by least privilege, ensures confidentiality and regulatory compliance.

Adım Adım Çözüm

1
Identify the data classification and regulatory scope.
The data consists of EU resident personal records (national IDs, bank details, addresses), which constitutes Personally Identifiable Information (PII) under GDPR.
Regulatory frameworks require specific security controls based on the data category being processed.
2
Determine the mandatory compliance controls for PII under GDPR.
GDPR mandates technical protections such as encryption for data at rest and in transit, as well as access controls based on least privilege.
Encryption safeguards confidentiality even if physical or network barriers are bypassed.
3
Evaluate the proposed options against compliance standard requirements.
Applying strong end-to-end encryption and strict permission management directly satisfies the compliance mandate.
Alternative measures like plaintext local transmission or leaving unique identifiers unencrypted fail compliance standards.

Anahtar Kavram

Data Privacy Regulations (GDPR and PII Protection)
Tahmini Süre:1m 30s
Bu soruyu puanla