nerdexam
Isaca

CGEIT · Question #125

An IT steering committee wants the enterprise's mobile workforce to use cloud-based file storage to save non-sensitive corporate data, removing the need for remote access to that information. Before…

The correct answer is A. A mandate for periodic employee training on how to classify corporate data files. Before implementing cloud-based storage for non-sensitive data, the data management policy must mandate periodic employee training on data classification to ensure users correctly identify and handle data appropriately.

Submitted by alyssa_d· Apr 18, 2026Governance of Enterprise IT

Question

An IT steering committee wants the enterprise's mobile workforce to use cloud-based file storage to save non-sensitive corporate data, removing the need for remote access to that information. Before this change is implemented, what should be included in the data management policy?

Options

  • AA mandate for periodic employee training on how to classify corporate data files
  • BA mandate for the encryption of all corporate data files at rest that contain sensitive data
  • CA process for blocking access to cloud based apps if inappropriate content is discovered
  • DA requirement to scan approved loud-based apps for inappropriate content

How the community answered

(30 responses)
  • A
    83% (25)
  • B
    3% (1)
  • C
    3% (1)
  • D
    10% (3)

Why each option

Before implementing cloud-based storage for non-sensitive data, the data management policy must mandate periodic employee training on data classification to ensure users correctly identify and handle data appropriately.

AA mandate for periodic employee training on how to classify corporate data filesCorrect

Since the plan is to store non-sensitive data in the cloud, employees must be able to accurately distinguish between sensitive and non-sensitive data to prevent misclassification and the inadvertent exposure of sensitive information. Periodic training ensures continuous awareness and adherence to data classification guidelines, which is fundamental to the security and compliance of any data storage strategy, especially when involving cloud services.

BA mandate for the encryption of all corporate data files at rest that contain sensitive data

While encryption of sensitive data at rest is a good practice, the question specifically states the cloud storage is for non-sensitive corporate data, making classification training a more immediate and relevant policy requirement to prevent sensitive data from ending up there.

CA process for blocking access to cloud based apps if inappropriate content is discovered

A process for blocking access to cloud-based apps if inappropriate content is discovered is an enforcement mechanism for data usage, but it doesn't address the primary need to ensure employees classify data correctly before it's stored.

DA requirement to scan approved loud-based apps for inappropriate content

A requirement to scan approved cloud-based apps for inappropriate content is a monitoring activity, which is important but secondary to ensuring users correctly classify and store data according to policy from the outset.

Concept tested: Data classification policy and user responsibility

Topics

#Data Classification#Data Management Policy#Cloud Storage#Employee Training

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice