0651
During an authorized retail-company assessment (RET-LAB-M01-651), which risk is most directly associated with "data-protection policy and law"?
View answer choices
- Unauthorized collection or exposure can harm individuals and create regulatory liability.
- A control focused on only one objective can leave the other security objectives exposed.
- Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
- Failure to protect cardholder data can lead to fraud, contractual penalties, and loss of processing trust.