exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 6 discussion

Actual exam question from CompTIA's CAS-004
Question #: 6
Topic #: 1
[All CAS-004 Questions]

A company is preparing to deploy a global service.
Which of the following must the company do to ensure GDPR compliance? (Choose two.)

  • A. Inform users regarding what data is stored.
  • B. Provide opt-in/out for marketing messages.
  • C. Provide data deletion capabilities.
  • D. Provide optional data encryption.
  • E. Grant data access to third parties.
  • F. Provide alternative authentication techniques.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Winterz
Highly Voted 3 years, 2 months ago
Selected Answer: AC
I would go with A and C as Erasure is part of GDPR compliance. A citizen has the right to request their data be deleted.
upvoted 15 times
...
bangz23
Highly Voted 2 years, 8 months ago
Selected Answer: AC
GDPR requires, Transparency on data you collect and store. Furthermore users need to have the an option to completely erase or copy their data if they decide opt out
upvoted 8 times
...
blacksheep6r
Most Recent 2 months, 3 weeks ago
Selected Answer: AC
A. Inform users regarding what data is stored: Under GDPR, one of the core principles is transparency. Organizations must clearly inform users about what personal data is being collected, stored, and how it will be used. This ensures that data subjects are aware of the data processing activities affecting their personal data. C. Provide data deletion capabilities: GDPR grants data subjects the "right to be forgotten," which means they can request the deletion of their personal data under certain circumstances. Ensuring that users can have their data deleted is a critical requirement for GDPR compliance.
upvoted 1 times
...
blacksheep6r
2 months, 3 weeks ago
Selected Answer: A
A. Inform users regarding what data is stored: Under GDPR, one of the core principles is transparency. Organizations must clearly inform users about what personal data is being collected, stored, and how it will be used. This ensures that data subjects are aware of the data processing activities affecting their personal data.
upvoted 1 times
...
BiteSize
7 months ago
Selected Answer: AC
GDPR allows data to be requested for erasure and it is required to notify users how their information will be used, processed, and stored. Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 2 times
...
Delab202
7 months ago
Selected Answer: AC
To ensure GDPR (General Data Protection Regulation) compliance when deploying a global service, the company should consider the following options: A. Inform users regarding what data is stored: This is a key requirement under GDPR. Companies must be transparent about the data they collect, process, and store. Providing users with information about the types of data being stored and the purposes for which it is used is crucial for compliance. C. Provide data deletion capabilities: GDPR gives individuals the right to have their personal data erased under certain conditions. Therefore, the company should implement mechanisms to allow users to request the deletion of their data, and the company must comply with such requests in a timely manner.
upvoted 1 times
...
CraZee
7 months ago
Selected Answer: AC
Based on this site: https://advisera.com/articles/a-summary-of-10-key-gdpr-requirements/#:~:text=GDPR%20lays%20out%20responsibilities%20for%20organisations%20to%20ensure,an%20organisation%20is%20not%20complying%20with%20GDPR%20requirements. Going with A and C A: From "Lawful, fair and transparent processing" Transparent means that companies must inform data subjects about the processing activities on their personal data. C: From "Data subject rights" The data subjects have been assigned the right to ask the company what information it has about them, and what the company does with this information. In addition, a data subject has the right to ask for correction, object to processing, lodge a complaint, or even ask for the deletion or transfer of his or her personal data. I see nothing regarding opting in or out of marketing.
upvoted 1 times
...
23169fd
9 months, 2 weeks ago
Selected Answer: AC
A. Inform users regarding what data is stored: GDPR mandates transparency about data processing. Companies must inform users about what data is being collected, how it will be used, and who it will be shared with. C. Provide data deletion capabilities: Under GDPR, individuals have the right to be forgotten. This means companies must provide users with the ability to request the deletion of their personal data.
upvoted 2 times
...
loucrass
1 year ago
Selected Answer: AB
The correct answers are (A and B)
upvoted 1 times
...
HappyG
1 year, 1 month ago
Selected Answer: AB
A and B are most correct.
upvoted 1 times
...
PeteUtah
2 years, 2 months ago
Selected Answer: AC
The assumption is that this worldwide system is deliberately marketed at EU people. If so, A&C are the answers. If the system is not targeted at EU citizens (even if they could possibly use it), GDPR would not apply; 'worldwide' is a big place, covering lots of jurisdictions.
upvoted 2 times
...
practical_93
2 years, 3 months ago
Selected Answer: AC
When it comes to GDPR, the answer is AC
upvoted 3 times
...
Sloananne
2 years, 7 months ago
Selected Answer: AB
A,B Opt in/out is a thing under GDPR 22. Deletion capabilities have further requirements. Transparency is a no brainer.
upvoted 1 times
...
dangerelchulo
2 years, 7 months ago
Selected Answer: AB
GDPR does require now to have an opt-in/out for marketing messages. C although sounds correct it is not, you are not required to provide a capability to erase date, you just need to provide a way for user to request date. Capability means they can erase their own data but that is not true you will have to request through legal department to have all your data erased for update on the email GDPR see link below https://www.zettasphere.com/gdpr-consent-opt-in-examples/
upvoted 3 times
dangerelchulo
2 years, 7 months ago
This makes me not approve option C. Requests can be made by any means; there is no requirement for a request from a data subject to only be accepted when sent to a specific email address or to have a particular subject line. Organizations are then given a maximum of one calendar month to respond to the request. https://www.gdpreu.org/gdpr-requirements/ B is the right choice https://www.gdpreu.org/compliance/email-marketing/
upvoted 1 times
...
...
ts260
2 years, 8 months ago
Selected Answer: AC
GDPT A and C
upvoted 3 times
...
Dassler
2 years, 9 months ago
Selected Answer: AC
B only refers to Spam.
upvoted 5 times
...
dangerelchulo
2 years, 10 months ago
Selected Answer: AC
A and C since opt out of spam is not part of the GDPR.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago