Courseiva
mediumMultiple Select

Key Elements of a Data Classification Policy

A security team is developing a data classification policy. Which TWO of the following elements should be included in the policy to ensure effective data governance?

⚠ Common exam trap

CompTIA often tests the distinction between policy elements (what the policy should contain) and derived controls (e.g., DLP rules, encryption algorithms), leading candidates to confuse operational implementation details with foundational policy components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Handling requirements for each classification level, including storage and transmission

Option E is correct because a data classification policy must define the criteria used to assign data into categories such as public, internal, and confidential, which is the foundational step that enables consistent labeling and governance across the organization. Option A is correct because once data is classified, the policy must specify handling requirements for each classification level, including how data is stored and transmitted, so that controls are applied proportionately to the data's sensitivity. Together, E and A establish the 'what' (classification criteria) and the 'how' (handling rules) that make a classification policy operational and enforceable. Option B is not the best fit because retention and disposal schedules are typically covered in a separate data retention policy, even though they relate to governance. Option C is not included because specific encryption algorithms are technical implementation details usually defined in cryptographic standards rather than in a classification policy. Option D is not included because DLP rules are operational enforcement mechanisms configured in tools, not policy-level classification elements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Handling requirements for each classification level, including storage and transmission

    Why this is correct

    Specifying handling requirements per classification level translates policy into enforceable controls for storage and transmission, satisfying the governance need for consistent protection. Without defined handling rules, classification labels alone cannot guide encryption, access, or sharing decisions across the data lifecycle.

  • ✗

    Data retention and disposal schedules

    Why it's wrong here

    Retention and disposal schedules govern lifecycle management of records, not the classification scheme itself. They are tempting because disposal depends on sensitivity labels, yet the policy must first define classification levels, criteria and handling rules before retention periods can be assigned.

  • ✗

    Encryption algorithms to be used for data at rest

    Why it's wrong here

    Encryption algorithms are a technical control applied at implementation, not a governance element defining classification tiers, handling rules or ownership. It is tempting because encryption protects data at rest, but that belongs in a security standard; a classification policy specifies labels, criteria and handling requirements instead.

  • ✗

    Data loss prevention (DLP) rules

    Why it's wrong here

    DLP rules are enforcement controls applied to data in motion or use, not classification elements defining sensitivity levels and handling requirements. They are tempting because DLP operationalises a classification scheme, but the policy itself must first define categories, owners and labelling criteria.

  • ✓

    Criteria for classifying data into categories such as public, internal, confidential

    Why this is correct

    Defining classification criteria establishes the objective basis for assigning data to public, internal, or confidential categories, which is the prerequisite for effective governance. Without explicit criteria, labelling becomes subjective and inconsistent, undermining every downstream control that depends on accurate classification.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.