ISC2 CISSP Asset Retention Data States DLP DRM And CASB Practice Test
2 Asset Security • 27 original questions
This CISSP practice test focuses on asset retention data states dlp drm and casb through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
Southridge Media is revising controls for its payment processing service. A review highlights Data Loss Prevention (DLP). The business continuity lead must address the control objective while ensuring that emergency access cannot become permanent access. Which action is the BEST next step? The asset inventory records 17,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data Loss Prevention (DLP) while ensuring that emergency access cannot become permanent access.
Option review:
A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data Loss Prevention (DLP) in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data Loss Prevention (DLP) while ensuring that emergency access cannot become permanent access.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data Loss Prevention (DLP) in this scenario.
D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Data Loss Prevention (DLP) in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
An auditor asks Adventure Works to demonstrate how it handles Cloud Access Security Broker (CASB) in the software delivery pipeline. The privacy and compliance lead must address the control objective while allowing independent verification of the control outcome. Which response is MOST appropriate? The asset inventory records 34,000 records across production and backup locations.
Correct answer: D
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Cloud Access Security Broker (CASB) while allowing independent verification of the control outcome.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Cloud Access Security Broker (CASB) in this scenario.
B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Cloud Access Security Broker (CASB) in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Cloud Access Security Broker (CASB) in this scenario.
D: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Cloud Access Security Broker (CASB) while allowing independent verification of the control outcome.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
After a business change, VanArsdel Energy discovers that End of life (EOL) is not handled consistently for the AI-assisted customer service platform. The security architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which recommendation BEST addresses the issue? The asset inventory records 51,000 records across production and backup locations.
Correct answer: A
Why: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of life (EOL) while accounting for third-party and lifecycle dependencies.
Option review:
A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of life (EOL) while accounting for third-party and lifecycle dependencies.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
Learning point: Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process. Excess retention increases exposure while unsupported assets accumulate unmanageable risk.
Northwind Health is preparing a security decision for the global collaboration platform. The decision involves End of support (EOS). The security operations manager must address the control objective while maintaining the organization’s stated risk appetite. Which option BEST reflects CISSP-level security practice? The asset inventory records 68,000 records across production and backup locations.
Correct answer: D
Why: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of support (EOS) while maintaining the organization’s stated risk appetite.
Option review:
A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of support (EOS) while maintaining the organization’s stated risk appetite.
Learning point: Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process. Excess retention increases exposure while unsupported assets accumulate unmanageable risk.
During a risk workshop for the e-commerce application, the team identifies Data in use as the deciding issue. The business continuity lead is expected to address the control objective while meeting the business objective with the least unnecessary operational complexity. What is the MOST appropriate course of action? The asset inventory records 85,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in use while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in use while meeting the business objective with the least unnecessary operational complexity.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
A control owner at A. Datum Analytics proposes a quick technical fix for Data in transit in the clinical records environment. The privacy and compliance lead must address the control objective while keeping the control sustainable for normal operations. What should happen FIRST? The asset inventory records 11,000 records across production and backup locations.
Correct answer: D
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in transit while keeping the control sustainable for normal operations.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
D: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in transit while keeping the control sustainable for normal operations.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
Blue Yonder Airlines is standardizing security across several business units. The remote access service raises a question about Data at rest. The security architect needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which action provides the BEST governance and security outcome? The asset inventory records 28,000 records across production and backup locations.
Correct answer: A
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data at rest while ensuring the decision can be repeated consistently across business units.
Option review:
A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data at rest while ensuring the decision can be repeated consistently across business units.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
During a business continuity exercise, City Power asks the security operations manager to address Scoping and tailoring for its customer identity platform. The requirement is to address the control objective while preserving clear accountability and audit evidence. What should the organization do FIRST? The asset inventory records 45,000 records across production and backup locations.
Correct answer: C
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Scoping and tailoring while preserving clear accountability and audit evidence.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Scoping and tailoring while preserving clear accountability and audit evidence.
D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
Tailspin Logistics is revising controls for its data analytics lake. A review highlights Standards selection. The business continuity lead must address the control objective while protecting sensitive data throughout the change. Which action is the BEST next step? The asset inventory records 62,000 records across production and backup locations.
Correct answer: A
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Standards selection while protecting sensitive data throughout the change.
Option review:
A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Standards selection while protecting sensitive data throughout the change.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
D: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
An auditor asks Alpine Sports to demonstrate how it handles Digital Rights Management (DRM) in the branch-office network. The privacy and compliance lead must address the control objective while preserving availability of the critical business service. Which response is MOST appropriate? The asset inventory records 79,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Digital Rights Management (DRM) while preserving availability of the critical business service.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Digital Rights Management (DRM) in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Digital Rights Management (DRM) while preserving availability of the critical business service.
C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Digital Rights Management (DRM) in this scenario.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Digital Rights Management (DRM) in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
After a business change, Fabrikam Manufacturing discovers that Data Loss Prevention (DLP) is not handled consistently for the industrial control network. The security architect needs to address the control objective without replacing governance with a technology-only shortcut. Which recommendation BEST addresses the issue? The asset inventory records 5,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data Loss Prevention (DLP) without replacing governance with a technology-only shortcut.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Data Loss Prevention (DLP) in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data Loss Prevention (DLP) without replacing governance with a technology-only shortcut.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data Loss Prevention (DLP) in this scenario.
D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data Loss Prevention (DLP) in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
Trey Research is preparing a security decision for the research data repository. The decision involves Cloud Access Security Broker (CASB). The security operations manager must address the control objective while keeping the process defensible to auditors and business owners. Which option BEST reflects CISSP-level security practice? The asset inventory records 22,000 records across production and backup locations.
Correct answer: D
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Cloud Access Security Broker (CASB) while keeping the process defensible to auditors and business owners.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Cloud Access Security Broker (CASB) in this scenario.
B: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Cloud Access Security Broker (CASB) in this scenario.
C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Cloud Access Security Broker (CASB) in this scenario.
D: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Cloud Access Security Broker (CASB) while keeping the process defensible to auditors and business owners.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
During a risk workshop for the payment processing service, the team identifies End of life (EOL) as the deciding issue. The business continuity lead is expected to address the control objective while minimizing irreversible action until facts and authority are established. What is the MOST appropriate course of action? The asset inventory records 39,000 records across production and backup locations.
Correct answer: B
Why: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of life (EOL) while minimizing irreversible action until facts and authority are established.
Option review:
A: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
B: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of life (EOL) while minimizing irreversible action until facts and authority are established.
C: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
Learning point: Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process. Excess retention increases exposure while unsupported assets accumulate unmanageable risk.
A control owner at Wide World Importers proposes a quick technical fix for End of support (EOS) in the software delivery pipeline. The privacy and compliance lead must address the control objective while preserving evidence needed for later review. What should happen FIRST? The asset inventory records 56,000 records across production and backup locations.
Correct answer: D
Why: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of support (EOS) while preserving evidence needed for later review.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
D: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of support (EOS) while preserving evidence needed for later review.
Learning point: Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process. Excess retention increases exposure while unsupported assets accumulate unmanageable risk.
Bellows University is standardizing security across several business units. The AI-assisted customer service platform raises a question about Data in use. The security architect needs to address the control objective without granting broader privilege than the business need requires. Which action provides the BEST governance and security outcome? The asset inventory records 73,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in use without granting broader privilege than the business need requires.
Option review:
A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in use without granting broader privilege than the business need requires.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
During a post-incident improvement program, Litware Services asks the security operations manager to address Data in transit for its global collaboration platform. The requirement is to address the control objective without creating a new single point of failure. What should the organization do FIRST? The asset inventory records 90,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in transit without creating a new single point of failure.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in transit without creating a new single point of failure.
C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
Humongous Insurance is revising controls for its e-commerce application. A review highlights Data at rest. The business continuity lead must address the control objective while ensuring that emergency access cannot become permanent access. Which action is the BEST next step? The asset inventory records 16,000 records across production and backup locations.
Correct answer: C
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data at rest while ensuring that emergency access cannot become permanent access.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data at rest while ensuring that emergency access cannot become permanent access.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
An auditor asks Woodgrove Bank to demonstrate how it handles Scoping and tailoring in the clinical records environment. The privacy and compliance lead must address the control objective while allowing independent verification of the control outcome. Which response is MOST appropriate? The asset inventory records 33,000 records across production and backup locations.
Correct answer: D
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Scoping and tailoring while allowing independent verification of the control outcome.
Option review:
A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
C: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
D: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Scoping and tailoring while allowing independent verification of the control outcome.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
After a business change, Relecloud Systems discovers that Standards selection is not handled consistently for the remote access service. The security architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which recommendation BEST addresses the issue? The asset inventory records 50,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Standards selection while accounting for third-party and lifecycle dependencies.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Standards selection while accounting for third-party and lifecycle dependencies.
C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
Contoso Financial is preparing a security decision for the customer identity platform. The decision involves End of life (EOL). The security operations manager must address the control objective while maintaining the organization’s stated risk appetite. Which option BEST reflects CISSP-level security practice? The asset inventory records 67,000 records across production and backup locations.
Correct answer: A
Why: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of life (EOL) while maintaining the organization’s stated risk appetite.
Option review:
A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of life (EOL) while maintaining the organization’s stated risk appetite.
B: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address End of life (EOL) in this scenario.
Learning point: Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process. Excess retention increases exposure while unsupported assets accumulate unmanageable risk.
During a risk workshop for the data analytics lake, the team identifies End of support (EOS) as the deciding issue. The business continuity lead is expected to address the control objective while meeting the business objective with the least unnecessary operational complexity. What is the MOST appropriate course of action? The asset inventory records 84,000 records across production and backup locations.
Correct answer: A
Why: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of support (EOS) while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. It directly addresses End of support (EOS) while meeting the business objective with the least unnecessary operational complexity.
B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
D: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address End of support (EOS) in this scenario.
Learning point: Retain assets only as long as business, legal, and regulatory requirements justify, and replace or retire unsupported assets through a controlled process. Excess retention increases exposure while unsupported assets accumulate unmanageable risk.
A control owner at Lamna Healthcare proposes a quick technical fix for Data in use in the branch-office network. The privacy and compliance lead must address the control objective while keeping the control sustainable for normal operations. What should happen FIRST? The asset inventory records 10,000 records across production and backup locations.
Correct answer: C
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in use while keeping the control sustainable for normal operations.
Option review:
A: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
B: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
C: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in use while keeping the control sustainable for normal operations.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data in use in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
Fourth Coffee is standardizing security across several business units. The industrial control network raises a question about Data in transit. The security architect needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which action provides the BEST governance and security outcome? The asset inventory records 27,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in transit while ensuring the decision can be repeated consistently across business units.
Option review:
A: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data in transit while ensuring the decision can be repeated consistently across business units.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
D: Handling controls should be derived from classification and remain consistent across the asset lifecycle. That action can be useful in a different security decision, but it does not most directly address Data in transit in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
During a quarterly security review, Consolidated Messenger asks the security operations manager to address Data at rest for its research data repository. The requirement is to address the control objective while preserving clear accountability and audit evidence. What should the organization do FIRST? The asset inventory records 44,000 records across production and backup locations.
Correct answer: D
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data at rest while preserving clear accountability and audit evidence.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
B: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Data at rest in this scenario.
D: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Data at rest while preserving clear accountability and audit evidence.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
Proseware Labs is revising controls for its payment processing service. A review highlights Scoping and tailoring. The business continuity lead must address the control objective while protecting sensitive data throughout the change. Which action is the BEST next step? The asset inventory records 61,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Scoping and tailoring while protecting sensitive data throughout the change.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Scoping and tailoring while protecting sensitive data throughout the change.
C: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
D: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Scoping and tailoring in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
An auditor asks Southridge Media to demonstrate how it handles Standards selection in the software delivery pipeline. The privacy and compliance lead must address the control objective while preserving availability of the critical business service. Which response is MOST appropriate? The asset inventory records 78,000 records across production and backup locations.
Correct answer: B
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Standards selection while preserving availability of the critical business service.
Option review:
A: Data protection obligations persist across the entire lifecycle and depend on clearly assigned owner/controller/custodian/processor responsibilities. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
B: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Standards selection while preserving availability of the critical business service.
C: Assets that are not owned and inventoried cannot be reliably governed, protected, patched, or retired. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Standards selection in this scenario.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
After a business change, Adventure Works discovers that Digital Rights Management (DRM) is not handled consistently for the AI-assisted customer service platform. The security architect needs to address the control objective without replacing governance with a technology-only shortcut. Which recommendation BEST addresses the issue? The asset inventory records 4,000 records across production and backup locations.
Correct answer: D
Why: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Digital Rights Management (DRM) without replacing governance with a technology-only shortcut.
Option review:
A: Excess retention increases exposure while unsupported assets accumulate unmanageable risk. That action can be useful in a different security decision, but it does not most directly address Digital Rights Management (DRM) in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Digital Rights Management (DRM) in this scenario.
C: Classification establishes the protection level and handling expectations needed for later controls. That action can be useful in a different security decision, but it does not most directly address Digital Rights Management (DRM) in this scenario.
D: Data protection methods are effective only when they match the data state and the actual compliance or handling requirement. It directly addresses Digital Rights Management (DRM) without replacing governance with a technology-only shortcut.
Learning point: Select data controls according to classification, data state, scope, and compliance needs, using DLP, DRM, CASB, encryption, or other controls where they fit. Data protection methods are effective only when they match the data state and the actual compliance or handling requirement.
Popular posts
Recent Posts
