ISC2 CISSP Information Classification Handling And Secure Provisioning Practice Test

 

2 Asset Security • 26 original questions

This CISSP practice test focuses on information classification handling and secure provisioning through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a risk workshop for the AI-assisted customer service platform, the team identifies Data classification as the deciding issue. The enterprise security engineer is expected to address the control objective while ensuring the decision can be repeated consistently across business units. What is the MOST appropriate course of action? The asset inventory records 86,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  3. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: A

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification while ensuring the decision can be repeated consistently across business units.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification while ensuring the decision can be repeated consistently across business units.

B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 2

A control owner at VanArsdel Energy proposes a quick technical fix for Asset classification in the global collaboration platform. The chief information security officer must address the control objective while preserving clear accountability and audit evidence. What should happen FIRST? The asset inventory records 12,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  4. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.

Correct answer: D

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while preserving clear accountability and audit evidence.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

C: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

D: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while preserving clear accountability and audit evidence.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 3

Northwind Health is standardizing security across several business units. The e-commerce application raises a question about Information and asset handling requirements. The risk manager needs to address the control objective while protecting sensitive data throughout the change. Which action provides the BEST governance and security outcome? The asset inventory records 29,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.

Correct answer: B

Why: Handling controls should be derived from classification and remain consistent across the asset lifecycle. It directly addresses Information and asset handling requirements while protecting sensitive data throughout the change.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. It directly addresses Information and asset handling requirements while protecting sensitive data throughout the change.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

Learning point: Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal. Handling controls should be derived from classification and remain consistent across the asset lifecycle.

Question 4

During a network segmentation redesign, Coho Insurance asks the security assurance manager to address Information and asset ownership for its clinical records environment. The requirement is to address the control objective while preserving availability of the critical business service. What should the organization do FIRST? The asset inventory records 46,000 records across production and backup locations.

  1. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  4. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.

Correct answer: A

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Information and asset ownership while preserving availability of the critical business service.

Option review:

A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Information and asset ownership while preserving availability of the critical business service.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 5

  1. Datum Analytics is revising controls for its remote access service. A review highlights Asset inventory including tangible and intangible assets. The enterprise security engineer must address the control objective without replacing governance with a technology-only shortcut. Which action is the BEST next step? The asset inventory records 63,000 records across production and backup locations.
  2. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  5. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.

Correct answer: A

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset inventory including tangible and intangible assets without replacing governance with a technology-only shortcut.

Option review:

A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset inventory including tangible and intangible assets without replacing governance with a technology-only shortcut.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 6

An auditor asks Blue Yonder Airlines to demonstrate how it handles Asset management in the customer identity platform. The chief information security officer must address the control objective while keeping the process defensible to auditors and business owners. Which response is MOST appropriate? The asset inventory records 80,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  3. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset management while keeping the process defensible to auditors and business owners.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset management while keeping the process defensible to auditors and business owners.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 7

After a business change, City Power discovers that Data classification is not handled consistently for the data analytics lake. The risk manager needs to address the control objective while minimizing irreversible action until facts and authority are established. Which recommendation BEST addresses the issue? The asset inventory records 6,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.

Correct answer: A

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification while minimizing irreversible action until facts and authority are established.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification while minimizing irreversible action until facts and authority are established.

B: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 8

Tailspin Logistics is preparing a security decision for the branch-office network. The decision involves Asset classification. The security assurance manager must address the control objective while preserving evidence needed for later review. Which option BEST reflects CISSP-level security practice? The asset inventory records 23,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.

Correct answer: A

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while preserving evidence needed for later review.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while preserving evidence needed for later review.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 9

During a risk workshop for the industrial control network, the team identifies Information and asset handling requirements as the deciding issue. The enterprise security engineer is expected to address the control objective without granting broader privilege than the business need requires. What is the MOST appropriate course of action? The asset inventory records 40,000 records across production and backup locations.

  1. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  2. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  3. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Handling controls should be derived from classification and remain consistent across the asset lifecycle. It directly addresses Information and asset handling requirements without granting broader privilege than the business need requires.

Option review:

A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. It directly addresses Information and asset handling requirements without granting broader privilege than the business need requires.

C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

Learning point: Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal. Handling controls should be derived from classification and remain consistent across the asset lifecycle.

Question 10

A control owner at Fabrikam Manufacturing proposes a quick technical fix for Information and asset ownership in the research data repository. The chief information security officer must address the control objective without creating a new single point of failure. What should happen FIRST? The asset inventory records 57,000 records across production and backup locations.

  1. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  2. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  3. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: B

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Information and asset ownership without creating a new single point of failure.

Option review:

A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Information and asset ownership without creating a new single point of failure.

C: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 11

Trey Research is standardizing security across several business units. The payment processing service raises a question about Asset inventory including tangible and intangible assets. The risk manager needs to address the control objective while ensuring that emergency access cannot become permanent access. Which action provides the BEST governance and security outcome? The asset inventory records 74,000 records across production and backup locations.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  3. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  4. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.

Correct answer: D

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset inventory including tangible and intangible assets while ensuring that emergency access cannot become permanent access.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset inventory including tangible and intangible assets while ensuring that emergency access cannot become permanent access.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 12

During a data-governance workshop, Margie Travel asks the security assurance manager to address Asset management for its software delivery pipeline. The requirement is to address the control objective while allowing independent verification of the control outcome. What should the organization do FIRST? The asset inventory records 91,000 records across production and backup locations.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  4. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.

Correct answer: C

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset management while allowing independent verification of the control outcome.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset management while allowing independent verification of the control outcome.

D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 13

Wide World Importers is revising controls for its AI-assisted customer service platform. A review highlights Data classification. The enterprise security engineer must address the control objective while accounting for third-party and lifecycle dependencies. Which action is the BEST next step? The asset inventory records 17,000 records across production and backup locations.

  1. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  2. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  3. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification while accounting for third-party and lifecycle dependencies.

Option review:

A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

B: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

C: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification while accounting for third-party and lifecycle dependencies.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 14

An auditor asks Bellows University to demonstrate how it handles Asset classification in the global collaboration platform. The chief information security officer must address the control objective while maintaining the organization’s stated risk appetite. Which response is MOST appropriate? The asset inventory records 34,000 records across production and backup locations.

  1. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  4. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.

Correct answer: C

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while maintaining the organization’s stated risk appetite.

Option review:

A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

C: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while maintaining the organization’s stated risk appetite.

D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 15

After a business change, Litware Services discovers that Information and asset handling requirements is not handled consistently for the e-commerce application. The risk manager needs to address the control objective while meeting the business objective with the least unnecessary operational complexity. Which recommendation BEST addresses the issue? The asset inventory records 51,000 records across production and backup locations.

  1. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  2. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  3. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: B

Why: Handling controls should be derived from classification and remain consistent across the asset lifecycle. It directly addresses Information and asset handling requirements while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. It directly addresses Information and asset handling requirements while meeting the business objective with the least unnecessary operational complexity.

C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

Learning point: Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal. Handling controls should be derived from classification and remain consistent across the asset lifecycle.

Question 16

Humongous Insurance is preparing a security decision for the clinical records environment. The decision involves Information and asset ownership. The security assurance manager must address the control objective while keeping the control sustainable for normal operations. Which option BEST reflects CISSP-level security practice? The asset inventory records 68,000 records across production and backup locations.

  1. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  2. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.

Correct answer: A

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Information and asset ownership while keeping the control sustainable for normal operations.

Option review:

A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Information and asset ownership while keeping the control sustainable for normal operations.

B: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 17

During a risk workshop for the remote access service, the team identifies Asset inventory including tangible and intangible assets as the deciding issue. The enterprise security engineer is expected to address the control objective while ensuring the decision can be repeated consistently across business units. What is the MOST appropriate course of action? The asset inventory records 85,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.

Correct answer: B

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset inventory including tangible and intangible assets while ensuring the decision can be repeated consistently across business units.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset inventory including tangible and intangible assets while ensuring the decision can be repeated consistently across business units.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 18

A control owner at Relecloud Systems proposes a quick technical fix for Asset management in the customer identity platform. The chief information security officer must address the control objective while preserving clear accountability and audit evidence. What should happen FIRST? The asset inventory records 11,000 records across production and backup locations.

  1. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  4. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.

Correct answer: D

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset management while preserving clear accountability and audit evidence.

Option review:

A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset management while preserving clear accountability and audit evidence.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 19

Contoso Financial is standardizing security across several business units. The data analytics lake raises a question about Data classification. The risk manager needs to address the control objective while protecting sensitive data throughout the change. Which action provides the BEST governance and security outcome? The asset inventory records 28,000 records across production and backup locations.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  4. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.

Correct answer: B

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification while protecting sensitive data throughout the change.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification while protecting sensitive data throughout the change.

C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 20

During a regulatory readiness assessment, Lucerne Publishing asks the security assurance manager to address Asset classification for its branch-office network. The requirement is to address the control objective while preserving availability of the critical business service. What should the organization do FIRST? The asset inventory records 45,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.
  4. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.

Correct answer: A

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while preserving availability of the critical business service.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while preserving availability of the critical business service.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 21

Lamna Healthcare is revising controls for its industrial control network. A review highlights Data classification. The enterprise security engineer must address the control objective without replacing governance with a technology-only shortcut. Which action is the BEST next step? The asset inventory records 62,000 records across production and backup locations.

  1. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.

Correct answer: B

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification without replacing governance with a technology-only shortcut.

Option review:

A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Data classification without replacing governance with a technology-only shortcut.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 22

An auditor asks Fourth Coffee to demonstrate how it handles Asset classification in the research data repository. The chief information security officer must address the control objective while keeping the process defensible to auditors and business owners. Which response is MOST appropriate? The asset inventory records 79,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: B

Why: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while keeping the process defensible to auditors and business owners.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. It directly addresses Asset classification while keeping the process defensible to auditors and business owners.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Asset classification in this scenario.

Learning point: Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner. Classification establishes the protection level and handling expectations needed for later controls.

Question 23

After a business change, Consolidated Messenger discovers that Information and asset handling requirements is not handled consistently for the payment processing service. The risk manager needs to address the control objective while minimizing irreversible action until facts and authority are established. Which recommendation BEST addresses the issue? The asset inventory records 5,000 records across production and backup locations.

  1. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  4. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.

Correct answer: C

Why: Handling controls should be derived from classification and remain consistent across the asset lifecycle. It directly addresses Information and asset handling requirements while minimizing irreversible action until facts and authority are established.

Option review:

A: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

C: Handling controls should be derived from classification and remain consistent across the asset lifecycle. It directly addresses Information and asset handling requirements while minimizing irreversible action until facts and authority are established.

D: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Information and asset handling requirements in this scenario.

Learning point: Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal. Handling controls should be derived from classification and remain consistent across the asset lifecycle.

Question 24

Proseware Labs is preparing a security decision for the software delivery pipeline. The decision involves Information and asset ownership. The security assurance manager must address the control objective while preserving evidence needed for later review. Which option BEST reflects CISSP-level security practice? The asset inventory records 22,000 records across production and backup locations.

  1. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  2. Assign data and asset classification based on sensitivity, value, legal obligations, and business impact under an accountable owner.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.

Correct answer: D

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Information and asset ownership while preserving evidence needed for later review.

Option review:

A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Information and asset ownership in this scenario.

D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Information and asset ownership while preserving evidence needed for later review.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 25

During a risk workshop for the AI-assisted customer service platform, the team identifies Asset inventory including tangible and intangible assets as the deciding issue. The enterprise security engineer is expected to address the control objective without granting broader privilege than the business need requires. What is the MOST appropriate course of action? The asset inventory records 39,000 records across production and backup locations.

  1. Define handling rules that follow the asset classification through access, storage, transmission, sharing, and disposal.
  2. Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.

Correct answer: D

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset inventory including tangible and intangible assets without granting broader privilege than the business need requires.

Option review:

A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Asset inventory including tangible and intangible assets in this scenario.

D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset inventory including tangible and intangible assets without granting broader privilege than the business need requires.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Question 26

A control owner at Adventure Works proposes a quick technical fix for Asset management in the global collaboration platform. The chief information security officer must address the control objective without creating a new single point of failure. What should happen FIRST? The asset inventory records 56,000 records across production and backup locations.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process.
  3. Apply lifecycle controls from collection through location, use, maintenance, retention, and secure destruction with the correct data roles.
  4. Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use.

Correct answer: D

Why: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset management without creating a new single point of failure.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

B: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Asset management in this scenario.

D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. It directly addresses Asset management without creating a new single point of failure.

Learning point: Establish ownership, inventory the asset, assign accountability, and provision it through an approved secure process before production use. Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired.

Popular posts

img