Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A multinational corporation must ensure that data…

A multinational corporation must ensure that data leaving the organization's network is classified and labeled appropriately. Which of the following is the MOST effective method to enforce consistent labeling across all data types?

⚠ Common exam trap

Watch out — candidates often confuse encryption (which protects data) with classification (which labels data), or they overestimate the effectiveness of training and manual processes for consistent enforcement at scale.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement automated data classification tools that scan for sensitive content and apply labels

Automated data classification tools (e.g., Microsoft Purview, Symantec DLP) use content inspection, pattern matching, and machine learning to scan data at rest, in use, and in transit. They apply consistent labels based on predefined policies (e.g., regex for PII, fingerprinting for IP), ensuring uniform labeling across all data types without relying on human consistency or manual effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement automated data classification tools that scan for sensitive content and apply labels

    Why this is correct

    Automated data classification tools are essential for a multinational corporation because they consistently identify and label sensitive content across diverse systems and jurisdictions. These tools leverage predefined rules, machine learning, and regular expressions to scan vast datasets, ensuring uniform application of data handling policies. This consistency is critical for maintaining regulatory compliance and enforcing appropriate security controls, regardless of where the data resides or travels.

  • Appoint data stewards in each department to manually review and label data

    Why it's wrong here

    Appointing data stewards for manual review and labeling is highly impractical and inefficient for a multinational corporation dealing with large volumes of data. This approach is prone to human error, subjective interpretation, and significant inconsistencies across departments and regions, making it impossible to achieve the necessary accuracy and speed for effective data governance. The sheer scale of modern enterprise data renders manual classification unscalable and unreliable for comprehensive protection.

  • Require all employees to complete annual training on data classification

    Why it's wrong here

    While crucial for fostering awareness and understanding of data classification policies, annual employee training alone does not guarantee consistent or accurate application of labels in practice. Human fallibility, oversight, and the sheer volume of data processed daily mean that employees may inadvertently misclassify or fail to label sensitive information, leading to significant gaps in data protection. Training is a foundational element, but it lacks the enforcement mechanism required for consistent, enterprise-wide data classification.

  • Encrypt all data in transit and at rest to prevent unauthorized access

    Why it's wrong here

    Encrypting all data in transit and at rest is a fundamental security control that protects confidentiality and integrity by rendering data unreadable to unauthorized parties. However, encryption operates independently of data classification; it does not inherently identify the *type* or *sensitivity* of the data (e.g., public, internal, confidential) or dictate its handling requirements. Classification provides the necessary context for applying appropriate security policies, which encryption alone cannot provide.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.