nerdexam
Isaca

CISA · Question #10

Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implemen

The correct answer is B. Develop an information classification scheme.. Before implementing email controls to prevent sensitive information exfiltration, the most crucial task is to develop an information classification scheme to define what data is considered sensitive and requires protection.

Submitted by emma.c· Apr 18, 2026Protection of Information Assets

Question

Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implementing any associated email controls?

Options

  • AProvide notification to employees about possible email monitoring.
  • BDevelop an information classification scheme.
  • CDevelop an acceptable use policy for end-user computing (EUC).
  • DRequire all employees to sign nondisclosure agreements (NDAs).

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    77% (27)
  • C
    14% (5)
  • D
    6% (2)

Why each option

Before implementing email controls to prevent sensitive information exfiltration, the most crucial task is to develop an information classification scheme to define what data is considered sensitive and requires protection.

AProvide notification to employees about possible email monitoring.

Notifying employees about monitoring is a legal and ethical consideration, but it doesn't define *what* sensitive data needs monitoring or protection.

BDevelop an information classification scheme.Correct

An information classification scheme provides the essential framework for identifying, labeling, and handling sensitive data. Without clearly defined classifications, it's impossible to consistently and effectively configure email controls to detect and prevent the unauthorized transmission of specific types of sensitive information, leading to either over-blocking or under-protection.

CDevelop an acceptable use policy for end-user computing (EUC).

An acceptable use policy is important for employee conduct but does not inherently define the technical characteristics of sensitive data that email controls need to enforce.

DRequire all employees to sign nondisclosure agreements (NDAs).

Requiring NDAs addresses legal protection and employee accountability but does not provide the technical basis for implementing automated controls to *prevent* data loss via email.

Concept tested: Data Loss Prevention (DLP) prerequisites, information classification

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide

Topics

#Information classification#Data protection#Email security#Data governance

Community Discussion

No community discussion yet for this question.

Full CISA Practice