exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 967 discussion

Actual exam question from Isaca's CISM
Question #: 967
Topic #: 1
[All CISM Questions]

An organization has multiple data repositories across different departments. The information security manager has been tasked with creating an enterprise strategy for protecting data. Which of the following information security initiatives should be the HIGHEST priority for the organization?

  • A. Data loss prevention (DLP)
  • B. Data retention strategy
  • C. Data encryption standards
  • D. Data masking
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
1 month ago
Selected Answer: C
Encryption should indeed be a higher priority than DLP when implementing strategies to protect data. While DLP is useful for monitoring and preventing data leaks, encryption provides foundational protection that ensures data confidentiality even if it is accessed or stolen.
upvoted 1 times
4 months, 2 weeks ago
Selected Answer: A
i think C can be part of A, isnt it?
upvoted 2 times
1 year ago
Selected Answer: A
Key word in the question is protect. DLP might not be the correct answer here. Why I say that is because the CISM has a very limited set of questions that involve technical tools. I could see them having C be the right answer, but I am going to be picking A if this question comes up. It protects data from both outsider and insider threats.
upvoted 1 times
1 year ago
Then again, encryption protects data even if leaked. Same as encrypted storage in a laptop - even if the laptop is lost (stolen, for example) and data is no longer under company's direct control, it's still protected.
upvoted 1 times
1 year, 1 month ago
Selected Answer: A
Although the question is vague as hell, I'll go with DLP just because it is the most comprehensive answer here (followed closely by C)
upvoted 1 times
1 year, 2 months ago
Is data protection - protect data from being deleted/removed or securing it? if protection is stopping data deletion/removal --> A If protection is security of data -----------------------------> C
upvoted 2 times
1 year, 1 month ago
Yep, the question is complete garbage and unfair.
upvoted 1 times
1 year ago
Also, if protection means following laws and regulations then it's B. Not enough details in the question to select a proper answer. Too many variables and scenarios are involved and not one of them is mentioned (outside of "across different departments" which was I assume supposed to be a hint, but it failed).
upvoted 1 times
1 year, 2 months ago
Selected Answer: C
encryption should be first and most important action b4 implementing DLP. without encryption data can be exposed. That should be first priority - encrypting data
upvoted 3 times
1 year, 3 months ago
A. Data loss prevention (DLP).....The question is focused on protecting the data as opposed to ensuring the confidentiality of the data. Even though the two sound similar, when the question doesn't mention confidentiality and focuses mainly on protecting the data, Data Loss Prevention (DLP) will take precedence over Data encryption. If the question had mentioned about ensuring the confidentiality of the data, i would have selected C. Data encryption.
upvoted 4 times
3 months ago
Yes correct
upvoted 1 times
1 year, 1 month ago
This makes sense...
upvoted 1 times
1 year, 3 months ago
Selected Answer: D
multiple data repositories across different departments - DLP alone won't guarantee anything as data is spread across the organization. Encryption standards as just that standards. - only actionable choice is Data Masking - Data masking is the process of obscuring or de-identifying sensitive data to protect it from unauthorized disclosure or access. This is crucial for organizations that handle large amounts of sensitive data, such as customer records, financial data, and personally identifiable information (PII).
upvoted 1 times
1 year, 4 months ago
Selected Answer: A
A: Data loss prevention (DLP) as the highest priority for the organization. Data loss prevention focuses on identifying, monitoring, and protecting sensitive data from unauthorized access, leakage, or loss. It helps prevent accidental or intentional data breaches by enforcing policies and controls that restrict the unauthorized transmission or storage of sensitive information.
upvoted 2 times
1 year, 4 months ago
Both A & C .....possible ...but i vote "A"
upvoted 3 times
1 year, 4 months ago
Selected Answer: A
A. Data loss prevention (DLP). Data loss prevention (DLP) is a crucial initiative for protecting sensitive data. It helps in detecting and preventing unauthorized access, use, and transmission of sensitive information. Given that the organization has multiple data repositories across different departments, implementing DLP measures can help in ensuring that sensitive data is not leaked, misused, or accessed by unauthorized individuals. It provides a proactive approach to safeguarding data and mitigating potential security breaches.
upvoted 2 times
1 year, 5 months ago
Selected Answer: C
Data encryption should be top priority because it protects confidentiality and integrity of data at rest and in transit, which also include data exfiltration. Though encryption doesn't prevent exfil itself, and DLP does, if a DLP fails, data that is not encrypted will expose confidential data.
upvoted 3 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago