mediumMultiple SelectObjective-mapped
CAS-004 Practice Question: A security team is developing a data…
A security team is developing a data classification policy. Which TWO of the following elements should be included in the policy to ensure effective data governance?
⚠ Common exam trap
CompTIA often tests the distinction between policy elements (what the policy should contain) and derived controls (e.g., DLP rules, encryption algorithms), leading candidates to confuse operational implementation details with foundational policy components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Handling requirements for each classification level, including storage and transmission
A data classification policy must define handling requirements for each classification level, specifying how data should be stored, transmitted, and accessed. This ensures consistent protection controls are applied based on sensitivity, which is a core governance principle. Without these requirements, data may be mishandled, leading to compliance violations or data breaches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Handling requirements for each classification level, including storage and transmission
Why this is correct
Specifies how data should be protected based on classification.
- ✗
Data retention and disposal schedules
Why it's wrong here
Retention schedules are often a separate policy.
- ✗
Encryption algorithms to be used for data at rest
Why it's wrong here
Encryption standards are typically part of a cryptographic policy.
- ✗
Data loss prevention (DLP) rules
Why it's wrong here
DLP is a control, not part of the classification policy itself.
- ✓
Criteria for classifying data into categories such as public, internal, confidential
Why this is correct
Defines the classification levels.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.