CAS-003 · Question #658
A company is deploying a DIP solution and scanning workstations and network drives for documents that contain potential Pll and payment card data. The results of the first scan are as follows: The…
The correct answer is A. Move the files from the marketing share to a secured drive. When sensitive files (PII, payment card data) are discovered on broadly accessible shared drives and data owners cannot be identified promptly, the immediate risk is unauthorized or excessive access. Moving the files to a secured drive with tightly controlled permissions…
Question
A company is deploying a DIP solution and scanning workstations and network drives for documents that contain potential Pll and payment card data. The results of the first scan are as follows:
The security learn is unable to identify the data owners for the specific files in a timely manner and does not suspect malicious activity with any of the detected files. Which of the following would address the inherent risk until the data owners can be formally identified?
Exhibit
Options
- AMove the files from the marketing share to a secured drive.
- BSearch the metadata for each file to locate the file's creator and transfer the files to the personal
- CConfigure the DLP tool to delete the files on the shared drives
- DRemove the access for the internal audit group from the accounts payable and payroll shares
How the community answered
(45 responses)- A80% (36)
- B11% (5)
- C4% (2)
- D4% (2)
Explanation
When sensitive files (PII, payment card data) are discovered on broadly accessible shared drives and data owners cannot be identified promptly, the immediate risk is unauthorized or excessive access. Moving the files to a secured drive with tightly controlled permissions reduces exposure without destroying potentially important data. This is a precautionary containment measure consistent with data protection principles. Searching metadata (B) is a useful investigation step but does not reduce risk in the interim. Configuring DLP to delete the files (C) is too destructive - files may be legitimate and needed once owners are identified. Removing internal audit access (D) only reduces one group's access and does not address the broader over-exposure problem.
Topics
Community Discussion
No community discussion yet for this question.
