CISSP Asset Security Practice Question
A company wants to ensure that data labeled 'Internal Use Only' is not inadvertently disclosed to unauthorized parties. What is the most effective way to communicate handling requirements to employees?
⚠ Common exam trap
CISSP often tests the difference between administrative controls (policy, training) and technical controls (DLP, encryption, RBAC)—candidates may pick a technical control when the question asks how to communicate requirements to people.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing a data classification policy and training employees on labeling and handling procedures
A data classification policy defines the categories (e.g., Public, Internal Use Only, Confidential) and the required handling procedures for each, and employee training ensures that everyone who creates or handles data knows how to label and protect it. This is the most effective way to communicate handling requirements because it establishes both the rule and the human behavior needed to follow it. Technical controls alone cannot fully prevent inadvertent disclosure by authorized users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using data loss prevention (DLP) software
Why it's wrong here
DLP software primarily serves as a technical enforcement mechanism, designed to detect and prevent unauthorized exfiltration or sharing of sensitive data based on predefined rules and patterns. While it can block actions, it does not proactively communicate the initial "internal use" handling requirements or educate employees on *why* certain data is classified as such and their associated responsibilities. It is a reactive control, not a foundational communication method for policy understanding.
- ✓
Implementing a data classification policy and training employees on labeling and handling procedures
Why this is correct
Implementing a robust data classification policy clearly defines what "internal use" data means, outlines specific labeling conventions, and details the mandatory handling procedures for such information. Coupled with comprehensive employee training, this approach directly communicates the organization's expectations and legal obligations to all personnel. This ensures employees understand their responsibilities and the implications of mishandling sensitive data, fostering a culture of compliance.
- ✗
Encrypting all data at rest
Why it's wrong here
Encrypting all data at rest is a critical technical control for protecting the confidentiality and integrity of information by rendering it unreadable without the correct decryption key. However, encryption alone does not convey the specific "internal use" handling requirements or restrictions to users once the data is accessed and decrypted. It secures the data's state, but doesn't educate individuals on appropriate usage, sharing, or disposal protocols.
- ✗
Restricting access to the data through role-based access control
Why it's wrong here
Role-based access control (RBAC) is an effective technical control for limiting *who* can access specific data based on their job function or role within the organization. While it restricts exposure, RBAC does not inherently communicate the detailed "internal use" handling policies or the specific responsibilities associated with accessing that data to authorized users. It manages permissions, but not the behavioral guidelines for data interaction.
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.