Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 416 discussion

Actual exam question from ISC's CISSP
Question #: 416
Topic #: 1
[All CISSP Questions]

A large international organization that collects information from its consumers has contracted with a Software as a Service (SaaS) cloud provider to process this data. The SaaS cloud provider uses additional data processing to demonstrate other capabilities it wishes to offer to the data owner. This vendor believes additional data processing activity is allowed since they are not disclosing to other organizations. Which of the following BEST supports this rationale?

  • A. The data was encrypted at all times and only a few cloud provider employees had access.
  • B. As the data owner, the cloud provider has the authority to direct how the data will be processed.
  • C. As the data processor, the cloud provider has the authority to direct how the data will be processed.
  • D. The agreement between the two parties is vague and does not detail how the data can be used.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
JohnyDal
Highly Voted 1 year, 9 months ago
Selected Answer: D
The large org is the data controller and CSP is its data processor. But data processors do not decide how to process data. Data Controller, the large org controls how data is to be processed. Based on the all given options, D is the best answer
upvoted 12 times
jackdryan
1 year, 6 months ago
I will go with D
upvoted 3 times
...
DapengZhang
1 year ago
such being the case, the answer shall be C. D imply that data processor takes advantage of agreement's vogue and not detailed. from your comment seems data processor has nature right to process the data in its own way.
upvoted 1 times
...
...
klarak
Most Recent 6 months, 3 weeks ago
Selected Answer: C
There’s no way D is an acceptable answer on an ISC2 exam.
upvoted 2 times
...
eboehm
7 months, 2 weeks ago
Selected Answer: C
Going with C as it is the only thing that comes close to providing a rationale from the vendors perspective. There is no indication that the contract was vague
upvoted 1 times
eboehm
7 months, 2 weeks ago
additionally, if they try to use D as their arguement then that is pretty much guaranteed to escalate things and most likely end up in a lawsuit
upvoted 1 times
...
...
GuardianAngel
9 months, 2 weeks ago
Options A, B, and C do not support the vendor’s rationale. Even if the data was encrypted (Option A), or the cloud provider has some authority over the data (Options B and C), this does not necessarily give them the right to use the data for purposes not agreed upon with the data owner.
upvoted 1 times
...
GuardianAngel
9 months, 2 weeks ago
In this scenario, the SaaS cloud provider is acting as a data processor, processing the data on behalf of the large international organization that collects the information. As the data processor, the cloud provider has the authority to direct how the data will be processed, within the boundaries and instructions provided by the data owner. The rationale behind the cloud provider's belief that additional data processing activity is allowed is based on the understanding that they have the authority to determine how the data will be processed as a data processor. This means that they can explore and demonstrate additional capabilities to the data owner without disclosing the data to other organizations.
upvoted 1 times
...
gjimenezf
9 months, 3 weeks ago
Selected Answer: D
The data CONTROLLER is the one who decides how the data will be processed.
upvoted 1 times
...
629f731
10 months, 1 week ago
Selected Answer: C
The answer that best supports the justification provided by the cloud service (SaaS) provider is: C. As a data processor, the cloud service provider has the authority to direct how the data will be processed. The relationship between a data controller (the data owner) and a data processor (the cloud service provider) is defined by legal authority and contractual agreements. Generally, the data controller is responsible for determining the purposes for which the data will be processed, while the data processor carries out the processing on behalf of the controller according to the instructions provided. In this case, option C reflects the idea that, as a data processor, the cloud service provider has the authority to direct how the data will be processed, but must do so in accordance with the instructions and contractual agreements established with the data controller.
upvoted 1 times
...
Soleandheel
11 months, 1 week ago
D. The agreement between the two parties is vague and does not detail how the data can be used.
upvoted 1 times
...
BestCommentorNA
1 year ago
Selected Answer: D
The GDPR defines a data processor as “a natural or legal person, public authority, agency, or other body, which processes personal data solely on behalf of the data controller.” In this context, the data controller is the person or entity that controls the processing of the data. The data controller decides what data to process, why this data should be processed, and how it is processed. As an example, a company that collects personal information on employees for payroll is a data controller. If they pass this information to a third-party company to process payroll, the payroll company is the data processor. In this example, the payroll company (the data processor) must not use the data for anything other than processing payroll at the direction of the data controller.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...