Soru

Zorluk: OrtaData Governance, Classification, and Privacy Controls

An aerospace engineering firm is updating its data governance framework for a repository containing proprietary aircraft blueprints and telemetry logs. The enterprise security team must clearly delineate operational execution tasks from high-level business accountability. Which of the following activities represent the primary responsibilities of a Data Custodian? (Select TWO.)

  1. Configuring technical security safeguards, system backups, and encryption at rest for the repositoryCevap
  2. Maintaining data integrity, performing routine patch management, and implementing network access rulesCevap
  3. C
    Determining the official data classification label and evaluating overall business impact for the dataset
  4. D
    Authenticating user identity credentials through single sign-on mechanisms before evaluating file access rights

Cevap

The primary operational responsibilities of a Data Custodian are configuring technical security safeguards, system backups, and encryption at rest, as well as maintaining data integrity, routine patch management, and network access rule implementation.
The Data Custodian is responsible for the operational management and technical protection of data assets. This includes implementing technical security controls (such as baseline encryption and access control rules), ensuring backup availability, maintaining system patches, and preserving data integrity according to the policies defined by the Data Owner.

Adım Adım Çözüm

1
Analyze the core responsibilities of the Data Custodian role
Identify that Data Custodians focus on operational and technical execution, maintaining the physical and logical security of assets as directed by policy.
CompTIA Security+ governance frameworks differentiate Data Owners (business accountability) from Data Custodians (technical execution).
2
Evaluate option choices against Data Custodian duties
Configuring backups, applying technical encryption controls, patching systems, and maintaining network access lists directly match technical custodianship.
These tasks involve system administration and hands-on maintenance of data containers.
3
Filter out Data Owner and general IAM infrastructure duties
Classifying data sensitivity belongs to Data Owners, while identity verification authentication belongs to general AAA identity services.
Data Owners hold ultimate legal and business authority over sensitivity labeling, whereas IAM handles authentication protocols.

Anahtar Kavram

Data Role Separation (Data Owner vs. Data Custodian)
Tahmini Süre:1m 30s
Bu soruyu puanla