ExamGecko
Question list
Search
Search

Related questions

Question 375 - CISA discussion

Report
Export

Which of the following should be the FRST step when developing a data toes prevention (DIP) solution for a large organization?

A.
Identify approved data workflows across the enterprise.
Answers
A.
Identify approved data workflows across the enterprise.
B.
Conduct a threat analysis against sensitive data usage.
Answers
B.
Conduct a threat analysis against sensitive data usage.
C.
Create the DLP pcJc.es and templates
Answers
C.
Create the DLP pcJc.es and templates
D.
Conduct a data inventory and classification exercise
Answers
D.
Conduct a data inventory and classification exercise
Suggested answer: D

Explanation:

The first step when developing a data loss prevention (DLP) solution for a large organization is to conduct a data inventory and classification exercise. This step is essential to identify the types, locations, owners, and sensitivity levels of the data that need to be protected by the DLP solution. A data inventory and classification exercise helps to define the scope, objectives, and requirements of the DLP solution, as well as to prioritize the data protection efforts based on the business value and risk of the data. A data inventory and classification exercise also enables the organization to comply with relevant laws and regulations regarding data privacy and security.

The other options are not the first step when developing a DLP solution, but rather subsequent steps that depend on the outcome of the data inventory and classification exercise. Identifying approved data workflows across the enterprise is a step that helps to design and implement the DLP policies and controls that match the business processes and data flows. Conducting a threat analysis against sensitive data usage is a step that helps to assess and mitigate the risks associated with data leakage, theft, or misuse. Creating the DLP policies and templates is a step that helps to enforce the data protection rules and standards across the organization.

ISACA CISA Review Manual 27th Edition (2019), page 247

Data Loss Prevention---Next Steps - ISACA1

What is data loss prevention (DLP)?| Microsoft Security

asked 18/09/2024
Leandro Zaneratto
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first