Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 54 discussion

Actual exam question from ISC's CISSP
Question #: 54
Topic #: 1
[All CISSP Questions]

Which of the following is the MOST appropriate control for asset data labeling procedures?

  • A. Categorizing the types of media being used
  • B. Logging data media to provide a physical inventory control
  • C. Reviewing off-site storage access controls
  • D. Reviewing audit trails of logging records
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
stickerbush1970
Highly Voted 2 years, 2 months ago
Selected Answer: A
Data categorization is a must for any organization.
upvoted 8 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
robervalchocolat
Most Recent 2 months, 3 weeks ago
most appropriate control for asset data labeling procedures because it helps to ensure that data is appropriately labeled and protected based on its sensitivity and value. Different types of media may require different levels of security, and categorizing them allows organizations to implement appropriate controls.
upvoted 1 times
...
deeden
3 months, 3 weeks ago
Selected Answer: B
Option B sounds more logical to me. Assets can easily get lost without inventory, and you can't protect what you don't have. I think there's a grey area here because labeling requires both classification and categorization of data. By classifying data based on sensitivity, value, and criticality, organizations can apply appropriate security controls and protection measures. This approach ensures that sensitive information is handled with the necessary care, REGARDLESS OF THE MEDIA ON WHICH IT IS STORED. Categorizing media types is still important for physical security and access controls, but it's a secondary consideration compared to data classification. Review is important during audits, not necessarily during data labeling.
upvoted 1 times
...
CCNPWILL
7 months, 1 week ago
A has to happen first before B. A is priority.
upvoted 1 times
...
YesPlease
11 months, 2 weeks ago
Selected Answer: A
Answer A) Classification versus Categorization: Classification by itself is simply a system of classes set up by an organization to differentiate asset values and, therefore, protection levels. The act of assigning a classification level to an asset is called categorization. Ideally, all assets should be categorized into a classification system to allow them to be protected based on value. https://destcert.com/resources/domain-2-asset-security/
upvoted 1 times
...
Vince_F_Fang
1 year, 2 months ago
Selected Answer: D
Isn't this issue about the control of the program itself
upvoted 4 times
50e940e
4 months, 3 weeks ago
correct, it is the control of PROCEDURE, instead of asset management
upvoted 1 times
...
...
Bach1968
1 year, 4 months ago
Selected Answer: A
The MOST appropriate control for asset data labeling procedures is option A: Categorizing the types of media being used. Asset data labeling procedures involve labeling and categorizing different types of media (such as physical storage devices, electronic media, or documents) to effectively manage and track data assets. Categorizing the types of media being used helps in identifying and distinguishing between different storage devices and media types, allowing for better organization and control. By categorizing the types of media, organizations can implement appropriate security controls and procedures tailored to each category. This includes assigning different levels of sensitivity or classification to data stored on specific media, implementing access controls based on media types, and applying specific handling and disposal procedures.
upvoted 3 times
...
HughJassole
1 year, 5 months ago
The question is asking "control for asset data labeling". So how to label data that is an asset, for example an application or a database with customer info. A CMDB does that, that's where you store all this info, and everything is a Configuration Item and has all relevant info. So the answer is B.
upvoted 2 times
...
Rollingalx
1 year, 8 months ago
I go with B. While categorizing the types of media being used and reviewing audit trails of logging records are important controls, it may not be as directly relevant to asset data labeling procedures as logging data media to provide a physical inventory control.
upvoted 3 times
...
s_n_
1 year, 9 months ago
The most appropriate control for asset data labeling procedures is B. Logging data media to provide physical inventory control. By logging the data media, organizations can keep track of all of the different types of media being used, such as CDs, USBs, hard drives, etc. Organizations can also use the logs to track the movement of data media within the organization, including any off-site storage access controls. Additionally, by logging data media, organizations can review audit trails of logging records to ensure that all data media is properly labeled and accounted for. Resources include National Institute of Standards and Technology (NIST) Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, and The National Archives, Guidance on the Management of Data Media Labeling.
upvoted 3 times
...
Billy235
1 year, 11 months ago
Question is asking about labeling procedures. Options B, C and D have nothing to do with a labeling procedure. Answer is A.
upvoted 2 times
...
Firedragon
2 years ago
Selected Answer: A
official study guide P190, Marking Sensitive Data and Assets labeling has nothing to do with audit logs
upvoted 3 times
...
Jimmyliu0822
2 years ago
Assestment
upvoted 1 times
...
Bhuraw
2 years ago
Selected Answer: D
Others seem irelevant
upvoted 1 times
...
DButtare
2 years, 2 months ago
Selected Answer: D
We are talking about the data itself not the medium
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...