1D0-571 · Question #52
You are creating an information security policy for your company. Which of the following activities will help you focus on creating policies for the most important resources?
The correct answer is D. Classifying systems. See the full explanation below for the reasoning.
Question
You are creating an information security policy for your company. Which of the following activities will help you focus on creating policies for the most important resources?
Options
- AAuditing the firewall
- BImplementing non-repudiation
- CLogging users
- DClassifying systems
How the community answered
(45 responses)- A7% (3)
- B2% (1)
- C11% (5)
- D80% (36)
Community Discussion
7D is correct. Before you write any security policy, you classify your systems first so you know which resources are most critical, most sensitive, or most regulated, and then you can focus your strongest policy controls on those high-value assets instead of treating every system the same.
Classifying systems tells you what matters most before you write a single policy line.
Classifying systems is the move here, and if you think about why, it clicks fast. You cannot write a meaningful security policy without first knowing which assets are sensitive, which are mission-critical, and which are basically throwaway. Auditing a firewall or logging users are operational controls that come after you already know what you are protecting and why. The other options are all downstream activities that assume classification has already happened. Here is what I genuinely want to understand better though: when your organization did its asset classification, did you find that the people doing the classifying (usually asset owners) consistently over-classified or under-classified their systems, and how did that affect the policies you ended up writing? I ask because I have a card in my deck right now that ties classification errors to policy gaps, and I am trying to figure out whether to split it into two cards or keep it as one.
Classification is the key step here because you cannot write meaningful policies around resources you have not yet ranked by value or sensitivity. Before you audit a firewall or set up logging, you need to know which systems actually matter most to the organization, and classifying them gives you that hierarchy. Non-repudiation and logging are good controls, but controls come after you have identified what you are protecting and why. When I sat for this exam I second-guessed myself and almost went with A because "auditing the firewall" sounded very security-policy-adjacent, but then I remembered that a firewall audit is a technical check, not a planning step, and D clicked into place the moment I framed the question as "what do you do first."
The word "first" in the stem is doing all the work here, because every distractor becomes the right answer eventually, so the exam is purely testing whether you understand the sequence, not whether those other controls have value.
Auditing the firewall is the right call here because when you go through a firewall audit you are forced to examine exactly what traffic is being permitted and denied, and that process naturally surfaces which systems and services are actually being protected and why. The CIW documentation on security policy development ties audit findings directly to identifying critical assets, so reviewing firewall rules gives you a concrete, technical baseline for determining where your policy efforts should be concentrated.
Hiroshi, the firewall audit is tempting because it feels technical and concrete, but it only shows you what is already being protected, not what actually matters most to the organization, and D gets you there directly by starting with a formal risk assessment that identifies and ranks critical assets before any technical controls enter the picture. The stem is asking about policy development sequence, and risk assessment comes first in that process.