ExamGecko
Question list
Search
Search

Related questions

Question 155 - CISA discussion

Report
Export

Which of the following would be to MOST concern when determine if information assets are adequately safequately safeguarded during transport and disposal?

A.
Lack of appropriate labelling
Answers
A.
Lack of appropriate labelling
B.
Lack of recent awareness training.
Answers
B.
Lack of recent awareness training.
C.
Lack of password protection
Answers
C.
Lack of password protection
D.
Lack of appropriate data classification
Answers
D.
Lack of appropriate data classification
Suggested answer: D

Explanation:

The most concerning issue when determining if information assets are adequately safeguarded during transport and disposal is lack of appropriate data classification. Data classification is a process that assigns categories or levels of sensitivity to different types of information assets based on their value, criticality, or risk to the organization. Data classification can help safeguard information assets during transport and disposal by providing criteria and guidelines for identifying, labeling, handling, and protecting information assets according to their sensitivity. Lack of appropriate data classification can compromise the security and confidentiality of information assets during transport and disposal by exposing them to unauthorized access, disclosure, theft, damage, or destruction. The other options are not as concerning as lack of appropriate data classification in safeguarding information assets during transport and disposal, as they do not affect the identification, labeling, handling, or protection of information assets according to their sensitivity. Lack of appropriate labeling is a possible factor that may increase the risk of misplacing, losing, or mishandling information assets during transport and disposal, but it does not affect the classification of information assets according to their sensitivity. Lack of recent awareness training is a possible factor that may affect the knowledge or behavior of staff involved in transporting or disposing of information assets, but it does not affect the classification of information assets according to their sensitivity. Lack of password protection is a possible factor that may affect the security or confidentiality of information assets stored on devices during transport and disposal, but it does not affect the classification of information assets according to their sensitivity.Reference:CISA Review Manual (Digital Version), Chapter 5, Section 5.3.2

asked 18/09/2024
Kabi Bashala
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first