Asset Security Question #277

Your organization is preparing to migrate several business units’ data to a centralized cloud data lake. During planning, the Chief Data Officer (CDO) notes that data from different departments use inconsistent labels — for example, “Customer ID” in Sales is called “Client Number” in Finance, and “User Identifier” in Marketing. The CISO expresses concern that this inconsistency could affect both data classification and access control. As the security manager, what is the most appropriate action to support secure and consistent data handling across the enterprise?

A. Implement data loss prevention (DLP) policies that automatically classify sensitive data during transfer.
B. Require each department to document its own classification scheme , enforcing GDPR requirements, before the migration.
C. Develop and enforce a unified enterprise data taxonomy to standardize terminology and metadata.
D. Restrict access to all datasets until classification inconsistencies are manually resolved
Domain Concept: Asset Security

This scenario evaluates management-level decision making in Asset Security. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top