exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 279 discussion

Actual exam question from ISC's CISSP
Question #: 279
Topic #: 1
[All CISSP Questions]

An organization has discovered that organizational data is posted by employees to data storage accessible to the general public. What is the PRIMARY step an organization must take to ensure data is properly protected from public release?

  • A. Implement a user reporting policy.
  • B. Implement a data encryption policy.
  • C. Implement a user training policy.
  • D. Implement a data classification policy.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 1 year, 11 months ago
Selected Answer: D
Agree with D, data classification is paramount for the organization.
upvoted 7 times
1 year, 3 months ago
D is correct
upvoted 1 times
Highly Voted 1 year, 11 months ago
Selected Answer: D
It should be D - Data Classification Policy
upvoted 5 times
Most Recent 3 months, 2 weeks ago
Selected Answer: C
I think it's C because this exam is supposed to be from a management level. D is a technical control. C is the corresponding administrative control. You can have data classification, but if your employees don't know how to use it, it may not do anything. You can implement automated data classification, but that's not what the question says.
upvoted 3 times
6 months, 1 week ago
D. A proper classification policy will cover user training
upvoted 1 times
8 months, 2 weeks ago
D. Implement a data classification policy. A data classification policy is essential for categorizing and labeling data based on its sensitivity and criticality. It helps organizations identify which data should be treated as confidential or restricted and which can be shared publicly. By classifying data appropriately, the organization can establish clear guidelines for handling, sharing, and protecting data.
upvoted 1 times
1 year, 4 months ago
Selected Answer: C
What if the employee has the right to access data?
upvoted 1 times
1 month ago
Then data classification policy should regulate how to handle or share the data.
upvoted 1 times
1 month ago
Then how do they know how to handle that data appropriately without properly training and practicing?
upvoted 1 times
1 year, 7 months ago
D. Implement a data classification policy. The primary step an organization must take to ensure data is properly protected from public release is to implement a data classification policy. This policy should clearly define what data is considered sensitive or confidential and establish guidelines for handling, storing, and sharing that data. Once the data has been properly classified, the organization can then take appropriate measures to secure it, such as implementing access controls, data encryption, and regular auditing to ensure compliance with the policy. In addition, user training on data classification and handling policies is also important to raise awareness and to make sure all employees understand their responsibilities in protecting the organizational data.
upvoted 4 times
1 year, 8 months ago
Selected Answer: C
According to the question about the data public release, i think the problem is not about the data but is the users
upvoted 4 times
9 months ago
But how the user will know what data ok to post and what data is not? Classification comes first.
upvoted 2 times
1 year, 8 months ago
even if you train the employees, they will still make mistakes. I would exclude option C. Option D is better.
upvoted 1 times
1 year, 9 months ago
Selected Answer: D
Data Classification supports all other elements of the Information Lifecycle (CSUSAD) but also can see here via elimination i.e. how would employees know what to report, encrypt or handle with special care if data is not classified?
upvoted 1 times
1 year, 9 months ago
The given answer is CORRECT!!!!!
upvoted 1 times
1 year, 9 months ago
True. D is the answer because why train employees on something you havent classified yet.
upvoted 1 times
1 year, 10 months ago
The PRIMARY step is to classified the data.
upvoted 1 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago