nerdexam
Isaca

CGEIT · Question #190

A major data leakage incident at an enterprise has resulted in a mandate to strengthen and enforce current data governance practices. Which of the following should be done FIRST to achieve this object

The correct answer is A. Assess data security controls.. To strengthen data governance after a data leakage incident, the initial step is to assess the existing data security controls.

Submitted by salim_om· Apr 18, 2026Governance of Enterprise IT

Question

A major data leakage incident at an enterprise has resulted in a mandate to strengthen and enforce current data governance practices. Which of the following should be done FIRST to achieve this objective?

Options

  • AAssess data security controls.
  • BReview data logs.
  • CAnalyze data quality.
  • DVerify data owners.

How the community answered

(56 responses)
  • A
    84% (47)
  • B
    9% (5)
  • C
    4% (2)
  • D
    4% (2)

Why each option

To strengthen data governance after a data leakage incident, the initial step is to assess the existing data security controls.

AAssess data security controls.Correct

After a data leakage, the immediate priority is to understand the vulnerabilities that led to the breach and identify gaps in existing security measures. Assessing data security controls provides a baseline of current protections and highlights areas requiring improvement to prevent future incidents and enforce data governance effectively.

BReview data logs.

Reviewing data logs is part of incident response and investigation, but it doesn't directly address strengthening and enforcing future governance practices as a first step; it's reactive analysis.

CAnalyze data quality.

Analyzing data quality is important for data governance but is less critical as a first step immediately after a data leakage incident, which points to security enforcement issues.

DVerify data owners.

Verifying data owners is a component of data governance but assessing the actual security controls protecting the data is a more fundamental and immediate first step after a leakage.

Concept tested: Incident response and data governance initiation

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-governance-strategy-overview

Topics

#Data Governance#Data Security#Security Controls#Incident Response

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice