exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 463 discussion

Actual exam question from Isaca's CISM
Question #: 463
Topic #: 1
[All CISM Questions]

Which of the following would BEST mitigate accidental data loss events?

  • A. Enforce a data hard drive encryption policy
  • B. Conduct a data loss prevention audit
  • C. Conduct periodic user awareness training
  • D. Obtain senior management support for the information security strategy
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AaronS1990
Highly Voted 1 year, 4 months ago
I would say A. I initially thought C but it's talking about accidental data loss here. That to me says it's an accident such as leaving a laptop/USB on a train and so encryption would mitigate some loss. The thing that troubles me with that answer is data isn't just in the for of media. Regardless, i don't see how training mitigates erroneous data loss
upvoted 6 times
...
Josef4CISM
Most Recent 1 month ago
Selected Answer: B
Everybody is discussing about A and C - but why not B? You need to identify what is causing the accidential data loss first through an audit. An audit will show you risks and provides recommendations, such as user awareness trainings or hard drive encryptions.
upvoted 1 times
...
e891cd1
5 months, 4 weeks ago
Accidental data lose can also be a staff member sent the wrong email to the wrong email address maybe the person from another company had the same name..only training can mitigate those events.
upvoted 2 times
...
Thavee
9 months ago
Selected Answer: C
There are several data loss incidents. Inadvertently deleted files, damaged tape backup due to the poor storage temp, human error wiping out the RAID during adding the new HDD into the RAID pool, lost notebooks/tablet, malicious software, and etc.
upvoted 4 times
...
yottabyte
9 months, 4 weeks ago
Selected Answer: A
Question asks about MITIGATION not PREVENTION.
upvoted 1 times
Thavee
9 months ago
nop. there is no concern. encryption is not mitigation at all but protection. no one would be able to crack the encrypted data/drive. Encryption is not mitigation.
upvoted 1 times
...
...
ats20
10 months, 3 weeks ago
Selected Answer: A
Enforcing data hard drive encryption policy is the best option for mitigating accidental data loss events. C does not mitigate.
upvoted 1 times
...
AlexJacobson
11 months, 3 weeks ago
Selected Answer: C
I'd say it's C. Data loss can also come in the form of ransomware infecting the network and encrypting data on workstations, servers and backups. Encryption of storage does indeed protect from data loss in case a user loses a laptop containing sensitive data in public transportation or it gets stolen. However, what about all other cases, like sending to the wrong email address, or mishandling data due to ignoring labeling, or leaving USB stick with sensitive data on a desk after hours (violating Clean desk policy)...? Data loss is a very broad term and from the given answers, C seems to be closest to the complete one.
upvoted 1 times
AlexJacobson
11 months, 3 weeks ago
One more thing (but it's more food for thought than anything else :): It can also actually be D! Because all other options are too focused to a particular data loss event or events, while D is basically saying "obtain support and buy-in for whatever needs to be done to prevent accidental data loss". I hate these vague questions, as I feel they're not exactly fair.
upvoted 1 times
Salilgen
10 months, 2 weeks ago
I understand your considerations but question is asking about mitigate. Data is already lost: training and senior support cannot help
upvoted 2 times
...
...
...
blehbleh
1 year ago
Selected Answer: C
I have to go C. Encryption on a hard drive is only good for the hard drive. Users send data via email, social media, SMS, and all other forms. Once it leaves the hard drive it is no longer encrypted therefore not solving all the problems. Especially since we all know users are the biggest weakness in any security expect. Therefore, I believe the answer to be C user training. Pretty much if you see a question that has to do with security and user training is an option on this test that will more then likely be the answer.
upvoted 2 times
...
jcisco123
1 year ago
Selected Answer: C
hard drive encryption is good for protecting data if a device is lost or stolen, but it doesn't prevent data loss due to accidental deletion or mismanagement.
upvoted 1 times
Thavee
9 months ago
Agreed, here is CISM, please do not focus much on technical things but managing.
upvoted 1 times
...
...
Uncle_Lucifer
1 year, 1 month ago
Selected Answer: A
A for sure. Training wont be better than encryption
upvoted 1 times
Thavee
9 months ago
Encryption would never help if a dumb worker deleted and emptied the bin all the HR/payroll files by mistake. This is always happening. That is why my IT Dept asked for Undeleted Software for server.
upvoted 1 times
...
...
acf4e9a
1 year, 2 months ago
Selected Answer: C
It is another vague question. It does not say user has lost the hard-disk or laptop because when accidental data loss, it could also mean, user might have sent an email with PII to unintended recipients so assuming it's vague, the closest action could be user awareness.
upvoted 1 times
...
Diekky
1 year, 5 months ago
Without the senior management support every other options would not have been possible
upvoted 1 times
...
Goseu
1 year, 6 months ago
Selected Answer: A
Obvious answer is A . Mitigation is the key word. C does nothing in that case.
upvoted 4 times
...
richck102
1 year, 6 months ago
Selected Answer: C
C. Conduct periodic user awareness training
upvoted 2 times
Jess20
1 year, 1 month ago
C prevents but doesn't mitigate
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago