Free CompTIA Security+ SY0-601 Practice Question

A retail company is developing a new customer rewards application that collects user information. The program will provide in-store credit equal to 1 percent of all purchases a customer makes. As the security advisor, you identify that the application is set to collect customer names, birth dates, email addresses, and purchasing history. To align with best practices for data minimization, what recommendation should you provide for the collection of customer data?

  • Remove the collection of birth dates, as it is not necessary for a rewards program.

  • Include address data to send personalized physical mail offers.

  • Collect customer social security numbers to ensure account security.

  • Increase data collection to include customers' workplace information for better marketing analysis.

This question's topic:
CompTIA Security+ SY0-601 / 
Governance, Risk, and Compliance
Your Score:

Check or uncheck an objective to set which questions you will receive.