Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISSP topic 1 question 54 discussion

Actual exam question from ISC's CISSP
Question #: 54
Topic #: 1
[All CISSP Questions]

Which of the following is the MOST appropriate control for asset data labeling procedures?

  • A. Categorizing the types of media being used
  • B. Logging data media to provide a physical inventory control
  • C. Reviewing off-site storage access controls
  • D. Reviewing audit trails of logging records
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
stickerbush1970
Highly Voted 1 year, 10 months ago
Selected Answer: A
Data categorization is a must for any organization.
upvoted 8 times
jackdryan
1 year, 1 month ago
A is correct
upvoted 1 times
...
...
CCNPWILL
Most Recent 2 months, 3 weeks ago
A has to happen first before B. A is priority.
upvoted 1 times
...
YesPlease
7 months ago
Selected Answer: A
Answer A) Classification versus Categorization: Classification by itself is simply a system of classes set up by an organization to differentiate asset values and, therefore, protection levels. The act of assigning a classification level to an asset is called categorization. Ideally, all assets should be categorized into a classification system to allow them to be protected based on value. https://destcert.com/resources/domain-2-asset-security/
upvoted 1 times
...
Vince_F_Fang
10 months, 2 weeks ago
Selected Answer: D
Isn't this issue about the control of the program itself
upvoted 4 times
50e940e
1 week, 1 day ago
correct, it is the control of PROCEDURE, instead of asset management
upvoted 1 times
...
...
Bach1968
1 year ago
Selected Answer: A
The MOST appropriate control for asset data labeling procedures is option A: Categorizing the types of media being used. Asset data labeling procedures involve labeling and categorizing different types of media (such as physical storage devices, electronic media, or documents) to effectively manage and track data assets. Categorizing the types of media being used helps in identifying and distinguishing between different storage devices and media types, allowing for better organization and control. By categorizing the types of media, organizations can implement appropriate security controls and procedures tailored to each category. This includes assigning different levels of sensitivity or classification to data stored on specific media, implementing access controls based on media types, and applying specific handling and disposal procedures.
upvoted 3 times
...
HughJassole
1 year ago
The question is asking "control for asset data labeling". So how to label data that is an asset, for example an application or a database with customer info. A CMDB does that, that's where you store all this info, and everything is a Configuration Item and has all relevant info. So the answer is B.
upvoted 2 times
...
Rollingalx
1 year, 3 months ago
I go with B. While categorizing the types of media being used and reviewing audit trails of logging records are important controls, it may not be as directly relevant to asset data labeling procedures as logging data media to provide a physical inventory control.
upvoted 3 times
...
s_n_
1 year, 5 months ago
The most appropriate control for asset data labeling procedures is B. Logging data media to provide physical inventory control. By logging the data media, organizations can keep track of all of the different types of media being used, such as CDs, USBs, hard drives, etc. Organizations can also use the logs to track the movement of data media within the organization, including any off-site storage access controls. Additionally, by logging data media, organizations can review audit trails of logging records to ensure that all data media is properly labeled and accounted for. Resources include National Institute of Standards and Technology (NIST) Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, and The National Archives, Guidance on the Management of Data Media Labeling.
upvoted 3 times
...
Billy235
1 year, 7 months ago
Question is asking about labeling procedures. Options B, C and D have nothing to do with a labeling procedure. Answer is A.
upvoted 2 times
...
Firedragon
1 year, 8 months ago
Selected Answer: A
official study guide P190, Marking Sensitive Data and Assets labeling has nothing to do with audit logs
upvoted 3 times
...
Jimmyliu0822
1 year, 8 months ago
Assestment
upvoted 1 times
...
Bhuraw
1 year, 8 months ago
Selected Answer: D
Others seem irelevant
upvoted 1 times
...
DButtare
1 year, 9 months ago
Selected Answer: D
We are talking about the data itself not the medium
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
ex Want to SAVE BIG on Certification Exam Prep?
close
ex Unlock All Exams with ExamTopics Pro 75% Off
  • arrow Choose From 1000+ Exams
  • arrow Access to 10 Exams per Month
  • arrow PDF Format Available
  • arrow Inline Discussions
  • arrow No Captcha/Robot Checks
Limited Time Offer
Ends in