Courseiva
Asset SecuritymediumMultiple ChoiceObjective-mapped

CISSP Asset Security Practice Question

A company wants to ensure that data labeled 'Internal Use Only' is not inadvertently disclosed to unauthorized parties. What is the most effective way to communicate handling requirements to employees?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implementing a data classification policy and training employees on labeling and handling procedures

Clear labeling and documented handling procedures ensure employees know how to treat data appropriately.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Using data loss prevention (DLP) software

    Why it's wrong here

    DLP software primarily serves as a technical enforcement mechanism, designed to detect and prevent unauthorized exfiltration or sharing of sensitive data based on predefined rules and patterns. While it can block actions, it does not proactively communicate the initial "internal use" handling requirements or educate employees on *why* certain data is classified as such and their associated responsibilities. It is a reactive control, not a foundational communication method for policy understanding.

  • Implementing a data classification policy and training employees on labeling and handling procedures

    Why this is correct

    Implementing a robust data classification policy clearly defines what "internal use" data means, outlines specific labeling conventions, and details the mandatory handling procedures for such information. Coupled with comprehensive employee training, this approach directly communicates the organization's expectations and legal obligations to all personnel. This ensures employees understand their responsibilities and the implications of mishandling sensitive data, fostering a culture of compliance.

  • Encrypting all data at rest

    Why it's wrong here

    Encrypting all data at rest is a critical technical control for protecting the confidentiality and integrity of information by rendering it unreadable without the correct decryption key. However, encryption alone does not convey the specific "internal use" handling requirements or restrictions to users once the data is accessed and decrypted. It secures the data's state, but doesn't educate individuals on appropriate usage, sharing, or disposal protocols.

  • Restricting access to the data through role-based access control

    Why it's wrong here

    Role-based access control (RBAC) is an effective technical control for limiting *who* can access specific data based on their job function or role within the organization. While it restricts exposure, RBAC does not inherently communicate the detailed "internal use" handling policies or the specific responsibilities associated with accessing that data to authorized users. It manages permissions, but not the behavioral guidelines for data interaction.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.