exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 222 discussion

Actual exam question from CompTIA's SY0-601
Question #: 222
Topic #: 1
[All SY0-601 Questions]

Which of the following is MOST likely to outline the roles and responsibilities of data controllers and data processors?

  • A. SSAE SOC 2
  • B. PCI DSS
  • C. GDPR
  • D. ISO 31000
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rodwave
Highly Voted 2 years, 7 months ago
Selected Answer: A
Answer: SSAE SOC 2 SSAE SOC 2(Standards of Attestations Engagement No. 16, System and Organizations Controls Report 2, Type 2) - auditing report that assesses how well organizations handle data security, system privacy, data confidentiality and data processing processes. ====================== GDPR (General Data Protection Regulation) - a regulation in EU laws that requires businesses to protect the personal data and privacy of EU citizens for transactions that occur within EU member states. The ISO 31000 Risk Management framework is an international standard that provides businesses with guidelines and principles for risk management from the International Organization for Standardization. PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards for organizations that handle credit cards.
upvoted 28 times
hieptran
2 years, 2 months ago
SSAE SOC 2 is a type of audit report that provides assurance about an organization's internal controls over data security, privacy, and confidentiality. While it may assess an organization's controls over data protection, it does not specifically outline the roles and responsibilities of data controllers and data processors. The roles and responsibilities of data controllers and data processors are specifically addressed under the GDPR, which is a comprehensive data protection regulation that was implemented in the European Union in 2018. The GDPR is designed to protect the privacy and personal data of individuals and provides specific guidelines for how organizations should handle personal data. As such, GDPR is more likely to outline the roles and responsibilities of data controllers and data processors than SSAE SOC 2.
upvoted 5 times
...
Sandon
2 years, 7 months ago
Statements on Standards for Attestation Engagements, Service Organization Control Type II*
upvoted 3 times
...
...
Gino_Slim
Highly Voted 2 years, 8 months ago
Selected Answer: C
I looked into this and a LOT of sources are saying GDPR. So, let's go with that guys. We can't all be wrong..........I mean we can't right? Right...?
upvoted 25 times
alwaysrollin247
2 years, 6 months ago
Well, the question doesn't say anything about EU and since GPDR is an EU regulation, the best alternate choice would be SSAE SOC 2. I mean honestly, don't you think this would be outlined in another source outside of the EU for the rest of the world?
upvoted 10 times
user82
2 years, 2 months ago
No but GDPR is the only choice that specifically deals with data controllers and data processors and SSAE SOC audits hoe an org uses data … I guess, I used chatgpt too
upvoted 3 times
user82
2 years, 2 months ago
I should add, it specifically said GDPR sets RULES for how personal data is used. Where SSAE SOC 2 is concerned with auditing how EFFECTIVE a service organization controls over its customer data
upvoted 2 times
...
...
...
...
LordJaraxxus
Most Recent 1 year, 3 months ago
Selected Answer: C
Personnel in specific data roles often need training on their roles and responsibilities. Some of these roles are GDPR-related. As a reminder, the GDPR applies to any organization that collects or processes data on any EU residents. Data controller. The data controller is the entity that determines why and how personal data should be processed. As an example, a business may outsource payroll. Data processor. A data processor is any entity that uses and manipulates the data on behalf of the data controller. A payroll company would accept the personal data from the data controller and use it to process payroll functions.
upvoted 1 times
...
TM78
1 year, 4 months ago
Selected Answer: C
C. GDPR Taken from Mike Meyers Security + 601 Cert Guide (pg 51): “The GDPR in the European Union outlines in great detail how organizations should deal with private information…Many countries have subsequently adopted similar regulations, so naturally, many multinational corporations comply with those regulations throughout their organization. The DATA CONTROLLER controls the data, which sounds silly, but means the person must ensure that data complies with the protections of PII thoroughly, according to the regulations in the GDPR.
upvoted 2 times
...
_deleteme_
1 year, 4 months ago
C - GDPR requires data breach notification within 72 hours, consent to be collected, and permits a user to withdraw consent from data collected, someone needs to control or process, and this is what a controller does. SOC 2 is just a suite of reports compiled based on criteria.
upvoted 2 times
...
shaneo007
1 year, 5 months ago
The question states Which of the following is MOST likely to outline the roles and responsibilities of data controllers and data processors? It doesn't mention anything about Countries states etc. Answer c.
upvoted 1 times
...
Maicalbert
1 year, 7 months ago
https://www.gdpreu.org/the-regulation/key-concepts/data-controllers-and-processors/
upvoted 4 times
...
ComPCertOn
1 year, 8 months ago
Selected Answer: C
GDPR is my first choice
upvoted 1 times
...
fercho2023
1 year, 8 months ago
If we agree in the below definition the answer is A : "SSAE-16 SOC 2 Type 2 stands for Standards of Attestations Engagement No. 16, System and Organizations Controls Report 2, Type 2. This AICPA-developed auditing report assesses how well organizations handle data security, system privacy, data confidentiality and data processing processes."
upvoted 1 times
...
TreeeSon
1 year, 9 months ago
Guys don't get caught up on locations it states "MOST likely to outline the roles and responsibilities of data controllers and data processors?" It isn't stating any exclusivity to a certain location, it's just asking which of the choices best contains the information.
upvoted 5 times
...
Slouja
1 year, 9 months ago
Selected Answer: C
If the question is focused on the overall security and control environment of service organizations, SSAE SOC 2 would be the appropriate choice.
upvoted 1 times
...
LinkinPark4evr
1 year, 9 months ago
Selected Answer: C
GDPR. If you go on the website for it then you can find the descriptions of data controller and data processor. The roles are required for compliance.
upvoted 1 times
...
malibi
1 year, 9 months ago
Selected Answer: C
The data controller, in essence, oversees how data is used, controls and supervises the duties of the data processor, and ensures that data is used, stored, and processed by the guidelines of the GDPR. They also oversee the process from obtaining data consent to enabling data usage for the required purposes.
upvoted 3 times
...
AmesCB
1 year, 11 months ago
GDPR should be the answer. one way to verify this will be to check the privacy policy of websites. there, you will see the responsibility of who handles users' data and how it should be handled, etc.
upvoted 1 times
...
Toominator
1 year, 11 months ago
Selected Answer: C
GDPR is the correct answer since it defines data roles.
upvoted 1 times
...
Abdul2107
1 year, 11 months ago
Selected Answer: C
C. GPDR Article 32 of GPDR discusses the roles of Data Processors and Data Controllers. https://gdpr-info.eu/art-32-gdpr/
upvoted 5 times
...
ApplebeesWaiter1122
1 year, 11 months ago
Selected Answer: C
The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that outlines the roles and responsibilities of data controllers and data processors. It governs the processing of personal data of EU citizens and residents and imposes strict requirements on how organizations handle and protect this data. The GDPR defines data controllers as entities that determine the purposes and means of the data processing, while data processors are entities that process personal data on behalf of the data controllers. The regulation lays out specific obligations and responsibilities for both data controllers and data processors to ensure the privacy and security of personal data.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...