exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 455 discussion

Actual exam question from ISC's CISSP
Question #: 455
Topic #: 1
[All CISSP Questions]

An organization is building an enterprise system using attribute-based access control (ABAC). To avoid inadvertent exposure, what should organizations do to ensure the proper handling of personally identifiable information (PII) and enforcement of PII regulations across the enterprise?

  • A. Employ trust agent.
  • B. Employ trust agreements.
  • C. Employ training program.
  • D. Employ regulations from leadership.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 1 year, 7 months ago
Selected Answer: C
C seems to be the best option to me for stopping inadvertent exposure.
upvoted 6 times
1 year, 4 months ago
C is correct
upvoted 1 times
Most Recent 5 months, 2 weeks ago
Selected Answer: C
if the question is 'what should organizations do to ensure the proper handling of personally identifiable information (PII) and enforcement of PII regulations across the enterprise?' answer B or D. But it asks 'To avoid inadvertent exposure, what should ~' , employee needs training to avoid inadvertent exposure.
upvoted 1 times
7 months ago
Selected Answer: C
Inadvertent exposure= lack of knowledge/ understanding.
upvoted 2 times
7 months, 1 week ago
Answer - Employ training program Just found this additional resouce and added it to the reference list. https://www.getcerta.com/blogs/abac-framework-building-compliance-from-scratch https://www.digitalguardian.com/dskb/how-secure-pii-against-loss-or-compromise https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-162.pdf
upvoted 1 times
7 months, 1 week ago
Answer - Employ training program The reason I'm choosing employ training program is that trust agreements are between organizations, not typically used internally for one corporation and the question says "accross the enterprise" The first link specifically mentions training and the second link talks about trust agreements across the trust chain (chain being multiple corporations not a single enterprise) https://www.digitalguardian.com/dskb/how-secure-pii-against-loss-or-compromise https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-162.pdf
upvoted 1 times
7 months, 2 weeks ago
Selected Answer: C
it is not asking about sharing PII to another organization, it is asking about handling PII by the employees of the organization that is with proper training of the employees, C
upvoted 1 times
7 months, 3 weeks ago
Selected Answer: B
The given answer B is correct. NIST SP 800-162 states the following: "Organizations engaged in attribute sharing should employ trust agreements to ensure the proper handling of PII and enforcement of PII regulations" Attribute Privacy Considerations page 26
upvoted 1 times
7 months, 2 weeks ago
it is not asking about sharing PII to another organization, it is asking about handling PII by the employees of the organization that is with proper training of the employees, C
upvoted 1 times
8 months, 2 weeks ago
Selected Answer: D
Answer D) Employ regulations from leadership. You guys are forgetting that this is a CISSP question..... A,B, and C all can fall under D (Employ regulations from leadership)
upvoted 2 times
5 months, 2 weeks ago
leadership doesnt make regulations, they make policies.. regulations come from regulatory agencies The answer is C.
upvoted 1 times
9 months ago
B. Employ trust agreements. Trust agreements, in the context of ABAC and PII handling, are contractual agreements or policies that specify how PII should be handled, who has access to it, and under what conditions. These agreements establish trust among data custodians, data processors, and other stakeholders involved in PII management. Trust agreements can define roles, responsibilities, and the conditions under which PII can be accessed or shared.
upvoted 3 times
9 months ago
Enforcing trust agreements within an organization typically involves a combination of legal, technical, and governance measures to ensure that the agreed-upon terms and conditions are adhered to.
upvoted 1 times
7 months, 3 weeks ago
Agreed, it is B. It is pretty much word for word in NIST 800-162 page 26.
upvoted 2 times
1 year, 3 months ago
I am going with D because the question states "attribute-based access control (ABAC)". This means that we can set access based on attributes, and those would come from management.
upvoted 1 times
1 year, 5 months ago
Selected Answer: D
Ensure and enforce. You can ensure by providing training but you can only enforce with regulations.
upvoted 3 times
1 year, 5 months ago
Selected Answer: B
B is correct. The key word here is enforcement. The training doesn't enforce anything.
upvoted 3 times
1 year, 7 months ago
Selected Answer: C
Train the group handling privacy
upvoted 4 times
9 months ago
Training will help ensure but will not enforce. The keywords in the question are ABAC, ensure and enforce. The only answer that addresses all 3 keywords is B. Employ trust agreements.
upvoted 1 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago