exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 192 discussion

Actual exam question from CompTIA's SY0-601
Question #: 192
Topic #: 1
[All SY0-601 Questions]

A social media company based in North America is looking to expand into new global markets and needs to maintain compliance with international standards.
With which of the following is the company's data protection officer MOST likely concerned?

  • A. NIST Framework
  • B. ISO 27001
  • C. GDPR
  • D. PCI-DSS
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jgp
Highly Voted 2 years, 11 months ago
Selected Answer: B
They don't specify Europe and ISO 27001 is the international standard
upvoted 42 times
DashRyde
1 year, 10 months ago
There are 27 member countries of the European Union (EU) you will expand your market globally even if your EU client are in different countries outside eurpoe like USA the GDPR law applies, second thing the question states the concerns of "Data protection Officer" not CISO. The answer is "C" feel free to share otherwise
upvoted 4 times
klinkklonk
1 year, 6 months ago
GDPR focuses on data protection while ISO 27001 is more for general information security. Plus GDPR is the strictest in the world, so if a company follows that then they will automatically comply with every other country in the world.
upvoted 2 times
...
...
a7d58aa
1 year, 5 months ago
the company's data protection officer MOST likely concerned
upvoted 2 times
...
...
Joe1984
Highly Voted 2 years, 11 months ago
This should be GDPR.
upvoted 25 times
BigLao
2 years, 9 months ago
No, GDPR is limited to Europe, question says, global market
upvoted 12 times
hrncgl
1 year, 11 months ago
Global Market is not the only criteria in the question. DPO's concern in that kind of scenario should be the GDPR when it is also highly possible expanding to Europe etc.
upvoted 4 times
RERE1
1 year, 11 months ago
Nowhere in the questions states there's need to expand to Europe. Dont decide the question.
upvoted 3 times
daddylonglegs
1 year, 10 months ago
No one is deciding the question. The point is that ISO compliance isn't mandatory, while GDPR is. The "World Market" includes Europe and if even a single customer is in the EU then it applies to the company. It's GDPR
upvoted 3 times
...
...
...
...
Gino_Slim
2 years, 9 months ago
It should not be Joe.
upvoted 16 times
daddylonglegs
1 year, 10 months ago
It should be Gino.
upvoted 1 times
...
JDawgBenet
2 years, 4 months ago
Tell em Gino
upvoted 5 times
...
...
...
csentry007
Most Recent 1 year ago
Why such trickery? GDPR is EU so do we assume they want to expand the want to those markets or pick the ISO standard?
upvoted 1 times
...
roukettas
1 year, 1 month ago
Selected Answer: B
Global is global ISO 27001 is the answer
upvoted 1 times
...
Dapsie
1 year, 2 months ago
ISO 27001 is broad and covers many other aspects of Information Security, unlike the GDPR, which deals with PII, and that should be the primary concern of the DPO of a Social Media company. Also, GDPR is extraterritorial, and wherever you go in the "global" market, you will always be concerned about any European citizen living there as they are still covered by GDPR regardless of the territory.
upvoted 1 times
...
6de42b3
1 year, 3 months ago
Selected Answer: C
It says concerned about which means GDPR not ISO. You follow ISO for guidance not because you have to like in the case of GDPR.
upvoted 3 times
...
Fart2023
1 year, 3 months ago
Selected Answer: C
Not every company has ISO 27001 nor it's a requirement to have, GDPR needs to be implemented and upheld if you are dealing with the EU.
upvoted 2 times
...
JackyCIT
1 year, 4 months ago
ChatGPT Based on "Data protection officer": "GDPR directly focuses on compliance with data protection regulations, making GDPR the most appropriate choice in that context." Based on "North America is looking to expand into new global markets": "GDPR applies not only to organizations based within the European Union (EU) but also to organizations outside the EU that process the personal data of individuals within the EU. Therefore, if the social media company based in North America is expanding into global markets, including those within the EU, it would need to ensure compliance with GDPR to handle the personal data of EU residents appropriately." This was tricky, but I'm going with (C) GDPR.
upvoted 1 times
...
LordJaraxxus
1 year, 5 months ago
Selected Answer: C
The data protection officer (DPO) is a role identified in the GDPR. This person is responsible for ensuring the organization is complying with all relevant laws. This person in this role also needs to act as an independent advocate for customer data.
upvoted 3 times
...
fryderyk
1 year, 5 months ago
Selected Answer: B
The question asks about international standards. GDPR is an EU regulation. ISO/IEC 27001 is an international standard to manage information security published by the International Organization for Standardization.
upvoted 1 times
...
SeWiz
1 year, 5 months ago
Selected Answer: B
I think GDPR is wrong on two accounts. 1) GDPR is not a standard, it is a regulation. 2)The question does not mention Europe. It mentions global expansion. ISO 27001 is relevant outside Europe and is a standard.
upvoted 1 times
toffer96
1 year, 3 months ago
It's a good point, the question is asking "compliance with international standards", not regulations.
upvoted 1 times
...
...
e098e9c
1 year, 5 months ago
Selected Answer: C
"A FYI --> With which of the following is the company's data protection officer MOST likely concerned?" DPO aka Data Protection Officer is explicitly required in the GDPR (Articles 37-39). For that, I have to go with C. Don't get fooled by "international standard" it is a good catch, but also catch the key word(s) in the proposed question. Good luck everyone!
upvoted 1 times
...
klinkklonk
1 year, 6 months ago
Selected Answer: C
GDPR focuses on data protection while ISO 27001 is more for general information security. Plus GDPR is the strictest in the world, so if a company follows that then they will automatically comply with every other country in the world.
upvoted 2 times
...
Jay987654
1 year, 7 months ago
Selected Answer: B
ISO 27001 is the world’s best-known standard for information security management systems (ISMS). It provides companies of any size and from all sectors of activity with guidance for establishing, implementing, maintaining, and continually improving an information security management system
upvoted 1 times
...
Ninja12345
1 year, 7 months ago
Selected Answer: B
They don't specify Europe and ISO 27001 is the international standard
upvoted 1 times
...
Ninja12345
1 year, 7 months ago
Selected Answer: B
They didn’t specify Europe and ISO 27001 is the international standard
upvoted 1 times
...
Rr_Jay
1 year, 7 months ago
Selected Answer: C
since DPO term is in GDPR
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...