Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 967 discussion

Actual exam question from Isaca's CISM
Question #: 967
Topic #: 1
[All CISM Questions]

An organization has multiple data repositories across different departments. The information security manager has been tasked with creating an enterprise strategy for protecting data. Which of the following information security initiatives should be the HIGHEST priority for the organization?

  • A. Data loss prevention (DLP)
  • B. Data retention strategy
  • C. Data encryption standards
  • D. Data masking
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
neo_wong
1 month ago
Selected Answer: A
i think C can be part of A, isnt it?
upvoted 2 times
...
POWNED
9 months, 2 weeks ago
Selected Answer: A
Key word in the question is protect. DLP might not be the correct answer here. Why I say that is because the CISM has a very limited set of questions that involve technical tools. I could see them having C be the right answer, but I am going to be picking A if this question comes up. It protects data from both outsider and insider threats.
upvoted 1 times
AlexJacobson
9 months, 2 weeks ago
Then again, encryption protects data even if leaked. Same as encrypted storage in a laptop - even if the laptop is lost (stolen, for example) and data is no longer under company's direct control, it's still protected.
upvoted 1 times
...
...
AlexJacobson
9 months, 3 weeks ago
Selected Answer: A
Although the question is vague as hell, I'll go with DLP just because it is the most comprehensive answer here (followed closely by C)
upvoted 1 times
...
Uncle_Lucifer
11 months, 1 week ago
Is data protection - protect data from being deleted/removed or securing it? if protection is stopping data deletion/removal --> A If protection is security of data -----------------------------> C
upvoted 2 times
AlexJacobson
9 months, 3 weeks ago
Yep, the question is complete garbage and unfair.
upvoted 1 times
...
AlexJacobson
9 months, 2 weeks ago
Also, if protection means following laws and regulations then it's B. Not enough details in the question to select a proper answer. Too many variables and scenarios are involved and not one of them is mentioned (outside of "across different departments" which was I assume supposed to be a hint, but it failed).
upvoted 1 times
...
...
Uncle_Lucifer
11 months, 1 week ago
Selected Answer: C
encryption should be first and most important action b4 implementing DLP. without encryption data can be exposed. That should be first priority - encrypting data
upvoted 3 times
...
Soleandheel
11 months, 3 weeks ago
A. Data loss prevention (DLP).....The question is focused on protecting the data as opposed to ensuring the confidentiality of the data. Even though the two sound similar, when the question doesn't mention confidentiality and focuses mainly on protecting the data, Data Loss Prevention (DLP) will take precedence over Data encryption. If the question had mentioned about ensuring the confidentiality of the data, i would have selected C. Data encryption.
upvoted 3 times
AlexJacobson
9 months, 3 weeks ago
This makes sense...
upvoted 1 times
...
...
Cyberbug2021
12 months ago
Selected Answer: D
multiple data repositories across different departments - DLP alone won't guarantee anything as data is spread across the organization. Encryption standards as just that standards. - only actionable choice is Data Masking - Data masking is the process of obscuring or de-identifying sensitive data to protect it from unauthorized disclosure or access. This is crucial for organizations that handle large amounts of sensitive data, such as customer records, financial data, and personally identifiable information (PII).
upvoted 1 times
...
koala_lay
1 year ago
Selected Answer: A
A: Data loss prevention (DLP) as the highest priority for the organization. Data loss prevention focuses on identifying, monitoring, and protecting sensitive data from unauthorized access, leakage, or loss. It helps prevent accidental or intentional data breaches by enforcing policies and controls that restrict the unauthorized transmission or storage of sensitive information.
upvoted 2 times
...
richck102
1 year ago
Both A & C .....possible ...but i vote "A"
upvoted 3 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: A
A. Data loss prevention (DLP). Data loss prevention (DLP) is a crucial initiative for protecting sensitive data. It helps in detecting and preventing unauthorized access, use, and transmission of sensitive information. Given that the organization has multiple data repositories across different departments, implementing DLP measures can help in ensuring that sensitive data is not leaked, misused, or accessed by unauthorized individuals. It provides a proactive approach to safeguarding data and mitigating potential security breaches.
upvoted 2 times
...
CISSPST
1 year, 1 month ago
Selected Answer: C
Data encryption should be top priority because it protects confidentiality and integrity of data at rest and in transit, which also include data exfiltration. Though encryption doesn't prevent exfil itself, and DLP does, if a DLP fails, data that is not encrypted will expose confidential data.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...