mediumMultiple Select
Key Elements of a Data Classification Policy
A security team is developing a data classification policy. Which TWO of the following elements should be included in the policy to ensure effective data governance?
⚠ Common exam trap
CompTIA often tests the distinction between policy elements (what the policy should contain) and derived controls (e.g., DLP rules, encryption algorithms), leading candidates to confuse operational implementation details with foundational policy components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Handling requirements for each classification level, including storage and transmission
Option E is correct because a data classification policy must define the criteria used to assign data into categories such as public, internal, and confidential, which is the foundational step that enables consistent labeling and governance across the organization. Option A is correct because once data is classified, the policy must specify handling requirements for each classification level, including how data is stored and transmitted, so that controls are applied proportionately to the data's sensitivity. Together, E and A establish the 'what' (classification criteria) and the 'how' (handling rules) that make a classification policy operational and enforceable. Option B is not the best fit because retention and disposal schedules are typically covered in a separate data retention policy, even though they relate to governance. Option C is not included because specific encryption algorithms are technical implementation details usually defined in cryptographic standards rather than in a classification policy. Option D is not included because DLP rules are operational enforcement mechanisms configured in tools, not policy-level classification elements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Handling requirements for each classification level, including storage and transmission
Why this is correct
Specifying handling requirements per classification level translates policy into enforceable controls for storage and transmission, satisfying the governance need for consistent protection. Without defined handling rules, classification labels alone cannot guide encryption, access, or sharing decisions across the data lifecycle.
- ✗
Data retention and disposal schedules
Why it's wrong here
Retention and disposal schedules govern lifecycle management of records, not the classification scheme itself. They are tempting because disposal depends on sensitivity labels, yet the policy must first define classification levels, criteria and handling rules before retention periods can be assigned.
- ✗
Encryption algorithms to be used for data at rest
Why it's wrong here
Encryption algorithms are a technical control applied at implementation, not a governance element defining classification tiers, handling rules or ownership. It is tempting because encryption protects data at rest, but that belongs in a security standard; a classification policy specifies labels, criteria and handling requirements instead.
- ✗
Data loss prevention (DLP) rules
Why it's wrong here
DLP rules are enforcement controls applied to data in motion or use, not classification elements defining sensitivity levels and handling requirements. They are tempting because DLP operationalises a classification scheme, but the policy itself must first define categories, owners and labelling criteria.
- ✓
Criteria for classifying data into categories such as public, internal, confidential
Why this is correct
Defining classification criteria establishes the objective basis for assigning data to public, internal, or confidential categories, which is the prerequisite for effective governance. Without explicit criteria, labelling becomes subjective and inconsistent, undermining every downstream control that depends on accurate classification.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.