mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: A security analyst discovers that a business unit…
A security analyst discovers that a business unit is storing sensitive data on a file share without classification labels. What is the first step to remediate?
⚠ Common exam trap
The trap here is that candidates often jump to technical controls (encryption, moving data) instead of recognizing that classification is a prerequisite governance step, as emphasized in the CISSP Asset Security domain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify the data owner to classify the data
The first step in remediating unclassified sensitive data is to notify the data owner, who is responsible for assigning classification labels based on organizational policy. Without classification, subsequent security controls (e.g., encryption, access controls) cannot be correctly applied because the data's sensitivity level is unknown. This aligns with the CISSP principle that data classification must precede protection mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Move the data to a secure server
Why it's wrong here
Moving data to a "secure server" without first understanding its classification (e.g., public, confidential, secret) and associated protection requirements is premature. The security analyst doesn't know what level of security is truly needed, nor if the new server meets those unknown requirements. This action could still expose sensitive data if the new server's controls are insufficient for its actual classification, or it could lead to over-securing public data, wasting valuable resources.
- ✗
Immediately delete the data
Why it's wrong here
Immediately deleting data without proper authorization from the data owner or a documented retention policy is a severe breach of data governance and could lead to significant operational disruption or legal repercussions. The security analyst's role is to identify risks and report them, not to unilaterally destroy organizational assets. Data classification is a prerequisite for determining appropriate retention and disposal policies, which must be followed to ensure compliance and prevent data loss.
- ✓
Notify the data owner to classify the data
Why this is correct
Notifying the data owner is the most appropriate first step because the data owner is ultimately accountable for the data's protection, including its classification. Classification dictates the appropriate security controls (e.g., encryption, access controls, retention policies) required to protect the data's confidentiality, integrity, and availability. Without proper classification, any security measures implemented would be based on assumptions rather than defined organizational policy and risk appetite, potentially leading to misallocated resources or inadequate protection.
- ✗
Encrypt the file share
Why it's wrong here
While encryption is a valuable security control, applying it to an entire file share without understanding the data's classification is a reactive measure that may be misapplied. Some data might not require encryption, while other data might need specific types of encryption (e.g., FIPS-validated, end-to-end) or additional controls beyond just file share encryption. Classification provides the necessary context to select and implement the most effective and appropriate security controls, ensuring resources are allocated efficiently and compliance requirements are met.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.