easyMultiple ChoiceObjective-mapped
CISSP Practice Question: Ensure that data is properly classified before…
A company wants to ensure that data is properly classified before storage. Which control should be implemented?
⚠ Common exam trap
Many exam-takers confuse a technical control (like encryption or DLP) with the administrative control (the policy) that governs classification, leading them to pick a tool instead of the foundational directive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Classification Policy
A Data Classification Policy is the foundational control that defines the categories (e.g., public, internal, confidential) and handling requirements for data before it is stored. Without a policy, technical controls like encryption or DLP lack the classification labels needed to apply the correct rules. The policy ensures that data owners and custodians consistently label data at creation or ingestion, enabling downstream security controls to function correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Classification Policy
Why this is correct
A Data Classification Policy is the foundational document that establishes an organization's framework for categorizing data based on its sensitivity, value, and regulatory requirements. It defines the classification levels (e.g., Public, Internal, Confidential), outlines the criteria for assigning data to each level, and specifies the corresponding handling, storage, and access requirements. This policy directly ensures that data is properly classified by providing the overarching guidance and procedures.
- ✗
Encryption
Why it's wrong here
Encryption is a cryptographic control designed to protect data confidentiality and integrity by transforming it into an unreadable format, both at rest and in transit. While essential for safeguarding sensitive information, encryption is a technical mechanism applied *after* data has been classified. It does not define the classification categories or assign sensitivity labels to data; rather, it is a protective measure whose application is often dictated by a data's classification.
- ✗
Data Loss Prevention (DLP)
Why it's wrong here
Data Loss Prevention (DLP) systems are technological tools used to monitor, detect, and prevent the unauthorized exfiltration or sharing of sensitive data from an organization's network or endpoints. DLP solutions often rely on pre-defined rules, content inspection, or existing classification tags to identify and protect sensitive information. However, DLP tools do not establish the initial data classification scheme or assign classification labels; they enforce policies based on classifications that have already been determined.
- ✗
Access Control Lists (ACLs)
Why it's wrong here
Access Control Lists (ACLs) are security mechanisms that specify which users or system processes are granted permission to access specific resources and what operations they can perform on those resources. ACLs are crucial for enforcing access restrictions and implementing the 'need-to-know' principle. While ACLs are often configured based on data classification levels to restrict access to sensitive information, they are an enforcement tool and do not define or assign the data classification itself.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.