Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: Ensure that data is properly classified before…

A company wants to ensure that data is properly classified before storage. Which control should be implemented?

⚠ Common exam trap

Many exam-takers confuse a technical control (like encryption or DLP) with the administrative control (the policy) that governs classification, leading them to pick a tool instead of the foundational directive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Classification Policy

A Data Classification Policy is the foundational control that defines the categories (e.g., public, internal, confidential) and handling requirements for data before it is stored. Without a policy, technical controls like encryption or DLP lack the classification labels needed to apply the correct rules. The policy ensures that data owners and custodians consistently label data at creation or ingestion, enabling downstream security controls to function correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Classification Policy

    Why this is correct

    A Data Classification Policy is the foundational document that establishes an organization's framework for categorizing data based on its sensitivity, value, and regulatory requirements. It defines the classification levels (e.g., Public, Internal, Confidential), outlines the criteria for assigning data to each level, and specifies the corresponding handling, storage, and access requirements. This policy directly ensures that data is properly classified by providing the overarching guidance and procedures.

  • Encryption

    Why it's wrong here

    Encryption is a cryptographic control designed to protect data confidentiality and integrity by transforming it into an unreadable format, both at rest and in transit. While essential for safeguarding sensitive information, encryption is a technical mechanism applied *after* data has been classified. It does not define the classification categories or assign sensitivity labels to data; rather, it is a protective measure whose application is often dictated by a data's classification.

  • Data Loss Prevention (DLP)

    Why it's wrong here

    Data Loss Prevention (DLP) systems are technological tools used to monitor, detect, and prevent the unauthorized exfiltration or sharing of sensitive data from an organization's network or endpoints. DLP solutions often rely on pre-defined rules, content inspection, or existing classification tags to identify and protect sensitive information. However, DLP tools do not establish the initial data classification scheme or assign classification labels; they enforce policies based on classifications that have already been determined.

  • Access Control Lists (ACLs)

    Why it's wrong here

    Access Control Lists (ACLs) are security mechanisms that specify which users or system processes are granted permission to access specific resources and what operations they can perform on those resources. ACLs are crucial for enforcing access restrictions and implementing the 'need-to-know' principle. While ACLs are often configured based on data classification levels to restrict access to sensitive information, they are an enforcement tool and do not define or assign the data classification itself.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.