CISSP Asset Security Practice Question
A company wants to ensure that data labeled 'Internal Use Only' is not inadvertently disclosed to unauthorized parties. What is the most effective way to communicate handling requirements to employees?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing a data classification policy and training employees on labeling and handling procedures
Clear labeling and documented handling procedures ensure employees know how to treat data appropriately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using data loss prevention (DLP) software
Why it's wrong here
DLP software primarily serves as a technical enforcement mechanism, designed to detect and prevent unauthorized exfiltration or sharing of sensitive data based on predefined rules and patterns. While it can block actions, it does not proactively communicate the initial "internal use" handling requirements or educate employees on *why* certain data is classified as such and their associated responsibilities. It is a reactive control, not a foundational communication method for policy understanding.
- ✓
Implementing a data classification policy and training employees on labeling and handling procedures
Why this is correct
Implementing a robust data classification policy clearly defines what "internal use" data means, outlines specific labeling conventions, and details the mandatory handling procedures for such information. Coupled with comprehensive employee training, this approach directly communicates the organization's expectations and legal obligations to all personnel. This ensures employees understand their responsibilities and the implications of mishandling sensitive data, fostering a culture of compliance.
- ✗
Encrypting all data at rest
Why it's wrong here
Encrypting all data at rest is a critical technical control for protecting the confidentiality and integrity of information by rendering it unreadable without the correct decryption key. However, encryption alone does not convey the specific "internal use" handling requirements or restrictions to users once the data is accessed and decrypted. It secures the data's state, but doesn't educate individuals on appropriate usage, sharing, or disposal protocols.
- ✗
Restricting access to the data through role-based access control
Why it's wrong here
Role-based access control (RBAC) is an effective technical control for limiting *who* can access specific data based on their job function or role within the organization. While it restricts exposure, RBAC does not inherently communicate the detailed "internal use" handling policies or the specific responsibilities associated with accessing that data to authorized users. It manages permissions, but not the behavioral guidelines for data interaction.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.