exam questions

Exam IIA-CIA-Part3 All Questions

View all questions & answers for the IIA-CIA-Part3 exam

Exam IIA-CIA-Part3 topic 2 question 231 discussion

Actual exam question from IIA's IIA-CIA-Part3
Question #: 231
Topic #: 2
[All IIA-CIA-Part3 Questions]

An organization decided to outsource its human resources function. As part of its process migration, the organization is implementing controls over sensitive employee data. What would be the most appropriate directive control in this area?

  • A. Require a Service Organization Controls (SOC) report from the service provider
  • B. Include a data protection clause in the contract with the service provider
  • C. Obtain a nondisclosure agreement from each employee at the service provider who will handle sensitive data
  • D. Encrypt the employee’s data before transmitting it to the service provider
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
emtofid
1 month ago
Selected Answer: B
Directive controls are policies, agreements, or guidelines that direct behavior and establish expectations to ensure compliance with security and privacy requirements.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago