How to Limit SaaS Document Access by High-Risk Country?
A company’s legal department drafted sensitive documents in a SaaS application and wants to ensure the documents cannot be accessed by individuals in high-risk countries. Which of the following is the most effective way to limit this access?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests which control enforces location-based access to a SaaS app, and the trap is confusing encryption or data sovereignty with an access restriction.
A geolocation policy is the most effective control when a SaaS application must prevent legal documents from being accessed from high-risk countries. This SY0-701 question tests country-based access restriction rather than data obfuscation, encryption, or legal residency requirements.
Many learners pick encryption because the documents are sensitive, but encryption protects confidentiality and does not stop an authorized user in a high-risk country from accessing the data after decryption.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A geolocation policy is the right control because the requirement is specifically to stop access by individuals in high-risk countries. SaaS platforms and identity providers can enforce location-based conditions using source IP geolocation, allowing access only from approved regions or blocking risky countries. This directly implements an access-control decision at authentication or session time rather than merely protecting the content. It can also be layered with MFA, device compliance, and risk signals for stronger enforcement.Why the Other Options Are Wrong
Data masking hides or obfuscates sensitive fields but does not prevent a user in a high-risk country from opening the document. Encryption protects the documents if they are intercepted or stolen, yet a user with valid credentials and decryption rights can still access them from anywhere. Data sovereignty regulation is a legal or compliance requirement about where data is stored or processed; it is not an operational control that blocks a specific user based on country. None of these options enforce geographic access restriction as directly as a geolocation policy.Community Comment Notes
Abcd123321 explains that geolocation protection can restrict or allow resource access based on the geographic location of users or devices. dbrowndiver notes that the SaaS app can use IP geolocation data to block connection attempts from high-risk countries. HungryRightNow cautions, "Ask Netflix how well a geolocation policy holds up to a VPN," which is a valid limitation, but it does not make the other options better for this scenario. PAWarriors ties the exact wording "high-risk COUNTRIES" to the geolocation policy choice.Official Reference
Exam Strategy
Look for wording about countries, regions, or geographic restrictions; that points to a location-based access control such as a geolocation policy. Eliminate encryption and data masking because they protect data content but do not enforce where a user can connect from.
Frequently Asked Questions
Why is encryption not enough to block access from high-risk countries?
Encryption protects data if intercepted or stolen, but a user in a high-risk country with valid credentials and keys can still open the document; you need an access control that enforces location.
Can a VPN bypass a SaaS geolocation policy?
Yes, a VPN or proxy can hide the user's true origin IP, so geolocation should be combined with MFA, device compliance, and risk-based signals.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →