Courseiva

CISM Data classification non-compliance Practice Question

An organization has a mature security program with documented policies and standards. However, during a recent audit, it was found that several business units are not following the mandated data classification standard. What is the MOST likely root cause?

⚠ Common exam trap

ISACA often tests the distinction between 'lack of awareness' and 'lack of enforcement'—the trap here is that candidates assume training is the solution to non-compliance, but in a mature program with documented policies, the root cause is almost always the absence of automated enforcement or consequences.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Lack of enforcement mechanisms

A mature security program with documented policies and standards indicates that the classification rules are already defined. The audit finding that business units are not following the mandated standard points to a failure in enforcement mechanisms—such as automated Data Loss Prevention (DLP) rules, access control policies, or mandatory labeling in SharePoint—rather than a lack of awareness or outdated policy. Without enforcement (e.g., Group Policy Objects blocking unclassified data uploads or SIEM alerts for missing classification tags), even well-trained staff may bypass the standard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inadequate security awareness training

    Why it's wrong here

    Training addresses awareness, but the stem describes business units knowingly not following a mandated standard within a mature programme, indicating governance and enforcement gaps rather than knowledge gaps. Awareness campaigns are correct when staff are genuinely unaware of their obligations.

  • ✓

    Lack of enforcement mechanisms

    Why this is correct

    Documented standards without monitoring, consequences, or automated controls let business units deviate unchecked. The absence of enforcement mechanisms, rather than unclear policy, explains why units are not following the mandated data classification standard despite a mature programme.

  • ✗

    Outdated data classification policy

    Why it's wrong here

    An outdated policy would be a documentation defect, yet the stem confirms policies and standards are current and mature; the failure is adherence, not content. Revision is correct when the standard itself no longer reflects data types or regulatory requirements.

  • ✗

    Insufficient budget for security tools

    Why it's wrong here

    Budget shortfalls affect tooling capability, not whether staff follow an existing mandated standard; the audit found behaviour gaps, not missing controls. Funding arguments fit scenarios where controls cannot be implemented at all, such as unaffordable monitoring or licensing.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.

✓Lack of enforcement mechanismsCorrect answer▾

Why this is correct

Documented standards without monitoring, consequences, or automated controls let business units deviate unchecked. The absence of enforcement mechanisms, rather than unclear policy, explains why units are not following the mandated data classification standard despite a mature programme.

✗Inadequate security awareness trainingWrong answer — click to see why▾

Why this is wrong here

Training may exist; the issue is lack of consequence for non-compliance.

✗Outdated data classification policyWrong answer — click to see why▾

Why this is wrong here

The policy is documented and mature; outdatedness is not indicated.

✗Insufficient budget for security toolsWrong answer — click to see why▾

Why this is wrong here

Budget may affect tools but not directly cause non-compliance with a standard.

Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.