Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A security analyst discovers that a business unit…

A security analyst discovers that a business unit is storing sensitive data on a file share without classification labels. What is the first step to remediate?

⚠ Common exam trap

The trap here is that candidates often jump to technical controls (encryption, moving data) instead of recognizing that classification is a prerequisite governance step, as emphasized in the CISSP Asset Security domain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Notify the data owner to classify the data

The first step in remediating unclassified sensitive data is to notify the data owner, who is responsible for assigning classification labels based on organizational policy. Without classification, subsequent security controls (e.g., encryption, access controls) cannot be correctly applied because the data's sensitivity level is unknown. This aligns with the CISSP principle that data classification must precede protection mechanisms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Move the data to a secure server

    Why it's wrong here

    Moving data to a "secure server" without first understanding its classification (e.g., public, confidential, secret) and associated protection requirements is premature. The security analyst doesn't know what level of security is truly needed, nor if the new server meets those unknown requirements. This action could still expose sensitive data if the new server's controls are insufficient for its actual classification, or it could lead to over-securing public data, wasting valuable resources.

  • Immediately delete the data

    Why it's wrong here

    Immediately deleting data without proper authorization from the data owner or a documented retention policy is a severe breach of data governance and could lead to significant operational disruption or legal repercussions. The security analyst's role is to identify risks and report them, not to unilaterally destroy organizational assets. Data classification is a prerequisite for determining appropriate retention and disposal policies, which must be followed to ensure compliance and prevent data loss.

  • Notify the data owner to classify the data

    Why this is correct

    Notifying the data owner is the most appropriate first step because the data owner is ultimately accountable for the data's protection, including its classification. Classification dictates the appropriate security controls (e.g., encryption, access controls, retention policies) required to protect the data's confidentiality, integrity, and availability. Without proper classification, any security measures implemented would be based on assumptions rather than defined organizational policy and risk appetite, potentially leading to misallocated resources or inadequate protection.

  • Encrypt the file share

    Why it's wrong here

    While encryption is a valuable security control, applying it to an entire file share without understanding the data's classification is a reactive measure that may be misapplied. Some data might not require encryption, while other data might need specific types of encryption (e.g., FIPS-validated, end-to-end) or additional controls beyond just file share encryption. Classification provides the necessary context to select and implement the most effective and appropriate security controls, ensuring resources are allocated efficiently and compliance requirements are met.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.