easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A multinational corporation must ensure that data…
A multinational corporation must ensure that data leaving the organization's network is classified and labeled appropriately. Which of the following is the MOST effective method to enforce consistent labeling across all data types?
⚠ Common exam trap
Watch out — candidates often confuse encryption (which protects data) with classification (which labels data), or they overestimate the effectiveness of training and manual processes for consistent enforcement at scale.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement automated data classification tools that scan for sensitive content and apply labels
Automated data classification tools (e.g., Microsoft Purview, Symantec DLP) use content inspection, pattern matching, and machine learning to scan data at rest, in use, and in transit. They apply consistent labels based on predefined policies (e.g., regex for PII, fingerprinting for IP), ensuring uniform labeling across all data types without relying on human consistency or manual effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement automated data classification tools that scan for sensitive content and apply labels
Why this is correct
Automated data classification tools are essential for a multinational corporation because they consistently identify and label sensitive content across diverse systems and jurisdictions. These tools leverage predefined rules, machine learning, and regular expressions to scan vast datasets, ensuring uniform application of data handling policies. This consistency is critical for maintaining regulatory compliance and enforcing appropriate security controls, regardless of where the data resides or travels.
- ✗
Appoint data stewards in each department to manually review and label data
Why it's wrong here
Appointing data stewards for manual review and labeling is highly impractical and inefficient for a multinational corporation dealing with large volumes of data. This approach is prone to human error, subjective interpretation, and significant inconsistencies across departments and regions, making it impossible to achieve the necessary accuracy and speed for effective data governance. The sheer scale of modern enterprise data renders manual classification unscalable and unreliable for comprehensive protection.
- ✗
Require all employees to complete annual training on data classification
Why it's wrong here
While crucial for fostering awareness and understanding of data classification policies, annual employee training alone does not guarantee consistent or accurate application of labels in practice. Human fallibility, oversight, and the sheer volume of data processed daily mean that employees may inadvertently misclassify or fail to label sensitive information, leading to significant gaps in data protection. Training is a foundational element, but it lacks the enforcement mechanism required for consistent, enterprise-wide data classification.
- ✗
Encrypt all data in transit and at rest to prevent unauthorized access
Why it's wrong here
Encrypting all data in transit and at rest is a fundamental security control that protects confidentiality and integrity by rendering data unreadable to unauthorized parties. However, encryption operates independently of data classification; it does not inherently identify the *type* or *sensitivity* of the data (e.g., public, internal, confidential) or dictate its handling requirements. Classification provides the necessary context for applying appropriate security policies, which encryption alone cannot provide.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.