How to Limit SaaS Document Access by High-Risk Country?

Given a scenario, select mitigation techniques or controls to secure an enterprise environment. Given a scenario, implement and maintain identity and access management.
Answer Correct answer: C — Implement a geolocation policy in the SaaS application to deny access from high-risk countries.

A company’s legal department drafted sensitive documents in a SaaS application and wants to ensure the documents cannot be accessed by individuals in high-risk countries. Which of the following is the most effective way to limit this access?

  1. Data masking
  2. Encryption
  3. Geolocation policy Correct Answer
  4. Data sovereignty regulation

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests which control enforces location-based access to a SaaS app, and the trap is confusing encryption or data sovereignty with an access restriction.

A geolocation policy is the most effective control when a SaaS application must prevent legal documents from being accessed from high-risk countries. This SY0-701 question tests country-based access restriction rather than data obfuscation, encryption, or legal residency requirements.

Many learners pick encryption because the documents are sensitive, but encryption protects confidentiality and does not stop an authorized user in a high-risk country from accessing the data after decryption.

Community Discussion (5 comments)

Abcd123321 👍 7 Selected: C
What is Geolocation Protection? Organizations may implement access control policies that restrict or allow access to certain resources based on the geographic location of users or devices. For example, they might limit access to sensitive systems only to users connecting from specific geographic regions or countries.
HungryRightNow 👍 2 Selected: C
Ask Netflix how well a geolocation policy holds up to a VPN
dbrowndiver 👍 4 Selected: C
Implementing a geolocation policy allows the company to configure the SaaS application to block access from IP addresses originating in high-risk countries. This is accomplished by using IP geolocation data to determine where a connection attempt is coming from. Geolocation policies are effective for preventing unauthorized access based on geographic location, ensuring that sensitive documents remain secure from individuals in regions identified as high-risk. Geolocation policies provide precise control over access based on the user’s location, making them an ideal solution for preventing access from specific countries while maintaining access for authorized users in safe regions that is why it is best for this situation.
PAWarriors 👍 1 Selected: C
Correct answer is C. "Documents cannot be accessed by individuals in high-risk COUNTRIES" --> Geolocation policy.
Zach123654 👍 2 Selected: C
GPT!!!!

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A geolocation policy is the right control because the requirement is specifically to stop access by individuals in high-risk countries. SaaS platforms and identity providers can enforce location-based conditions using source IP geolocation, allowing access only from approved regions or blocking risky countries. This directly implements an access-control decision at authentication or session time rather than merely protecting the content. It can also be layered with MFA, device compliance, and risk signals for stronger enforcement.

Why the Other Options Are Wrong

Data masking hides or obfuscates sensitive fields but does not prevent a user in a high-risk country from opening the document. Encryption protects the documents if they are intercepted or stolen, yet a user with valid credentials and decryption rights can still access them from anywhere. Data sovereignty regulation is a legal or compliance requirement about where data is stored or processed; it is not an operational control that blocks a specific user based on country. None of these options enforce geographic access restriction as directly as a geolocation policy.

Community Comment Notes

Abcd123321 explains that geolocation protection can restrict or allow resource access based on the geographic location of users or devices. dbrowndiver notes that the SaaS app can use IP geolocation data to block connection attempts from high-risk countries. HungryRightNow cautions, "Ask Netflix how well a geolocation policy holds up to a VPN," which is a valid limitation, but it does not make the other options better for this scenario. PAWarriors ties the exact wording "high-risk COUNTRIES" to the geolocation policy choice.

Official Reference

Exam Strategy

Look for wording about countries, regions, or geographic restrictions; that points to a location-based access control such as a geolocation policy. Eliminate encryption and data masking because they protect data content but do not enforce where a user can connect from.

Frequently Asked Questions

Why is encryption not enough to block access from high-risk countries?

Encryption protects data if intercepted or stolen, but a user in a high-risk country with valid credentials and keys can still open the document; you need an access control that enforces location.

Can a VPN bypass a SaaS geolocation policy?

Yes, a VPN or proxy can hide the user's true origin IP, so geolocation should be combined with MFA, device compliance, and risk-based signals.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide