Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 455 discussion

Actual exam question from ISC's CISSP
Question #: 455
Topic #: 1
[All CISSP Questions]

An organization is building an enterprise system using attribute-based access control (ABAC). To avoid inadvertent exposure, what should organizations do to ensure the proper handling of personally identifiable information (PII) and enforcement of PII regulations across the enterprise?

  • A. Employ trust agent.
  • B. Employ trust agreements.
  • C. Employ training program.
  • D. Employ regulations from leadership.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
yottabyte
Highly Voted 1 year, 9 months ago
Selected Answer: C
C seems to be the best option to me for stopping inadvertent exposure.
upvoted 6 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
Hongjun
Most Recent 7 months, 4 weeks ago
Selected Answer: C
if the question is 'what should organizations do to ensure the proper handling of personally identifiable information (PII) and enforcement of PII regulations across the enterprise?' answer B or D. But it asks 'To avoid inadvertent exposure, what should ~' , employee needs training to avoid inadvertent exposure.
upvoted 1 times
...
pete79
9 months, 2 weeks ago
Selected Answer: C
Inadvertent exposure= lack of knowledge/ understanding.
upvoted 2 times
...
GuardianAngel
9 months, 2 weeks ago
Answer - Employ training program Just found this additional resouce and added it to the reference list. https://www.getcerta.com/blogs/abac-framework-building-compliance-from-scratch https://www.digitalguardian.com/dskb/how-secure-pii-against-loss-or-compromise https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-162.pdf
upvoted 1 times
...
GuardianAngel
9 months, 2 weeks ago
Answer - Employ training program The reason I'm choosing employ training program is that trust agreements are between organizations, not typically used internally for one corporation and the question says "accross the enterprise" The first link specifically mentions training and the second link talks about trust agreements across the trust chain (chain being multiple corporations not a single enterprise) https://www.digitalguardian.com/dskb/how-secure-pii-against-loss-or-compromise https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-162.pdf
upvoted 1 times
...
gjimenezf
9 months, 3 weeks ago
Selected Answer: C
it is not asking about sharing PII to another organization, it is asking about handling PII by the employees of the organization that is with proper training of the employees, C
upvoted 1 times
...
SSimko
10 months ago
Selected Answer: B
The given answer B is correct. NIST SP 800-162 states the following: "Organizations engaged in attribute sharing should employ trust agreements to ensure the proper handling of PII and enforcement of PII regulations" 3.2.1.6 Attribute Privacy Considerations page 26
upvoted 1 times
gjimenezf
9 months, 3 weeks ago
it is not asking about sharing PII to another organization, it is asking about handling PII by the employees of the organization that is with proper training of the employees, C
upvoted 1 times
...
...
YesPlease
11 months ago
Selected Answer: D
Answer D) Employ regulations from leadership. You guys are forgetting that this is a CISSP question..... A,B, and C all can fall under D (Employ regulations from leadership)
upvoted 2 times
dm808
8 months ago
leadership doesnt make regulations, they make policies.. regulations come from regulatory agencies The answer is C.
upvoted 1 times
...
...
Soleandheel
11 months, 1 week ago
B. Employ trust agreements. Trust agreements, in the context of ABAC and PII handling, are contractual agreements or policies that specify how PII should be handled, who has access to it, and under what conditions. These agreements establish trust among data custodians, data processors, and other stakeholders involved in PII management. Trust agreements can define roles, responsibilities, and the conditions under which PII can be accessed or shared.
upvoted 3 times
SSimko
10 months ago
Agreed, it is B. It is pretty much word for word in NIST 800-162 page 26.
upvoted 2 times
...
Soleandheel
11 months, 1 week ago
Enforcing trust agreements within an organization typically involves a combination of legal, technical, and governance measures to ensure that the agreed-upon terms and conditions are adhered to.
upvoted 1 times
...
...
HughJassole
1 year, 5 months ago
I am going with D because the question states "attribute-based access control (ABAC)". This means that we can set access based on attributes, and those would come from management.
upvoted 1 times
...
aleXplicitly
1 year, 7 months ago
Selected Answer: D
Ensure and enforce. You can ensure by providing training but you can only enforce with regulations.
upvoted 3 times
...
Rollingalx
1 year, 8 months ago
Selected Answer: B
B is correct. The key word here is enforcement. The training doesn't enforce anything.
upvoted 3 times
...
JohnyDal
1 year, 9 months ago
Selected Answer: C
Train the group handling privacy
upvoted 4 times
Soleandheel
11 months, 1 week ago
Training will help ensure but will not enforce. The keywords in the question are ABAC, ensure and enforce. The only answer that addresses all 3 keywords is B. Employ trust agreements.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...