nerdexam
Isaca

CISA · Question #198

A startup organization wants to develop a data loss prevention (DLP) program. The FIRST step should be to implement:

The correct answer is C. data classification. Data classification must come first because you cannot protect data you haven't identified and categorized - without knowing what data is sensitive, critical, or public, any subsequent controls are applied blindly and inconsistently. Why the distractors are wrong: A (Security awa

Submitted by haru.x· Apr 18, 2026Protection of Information Assets

Question

A startup organization wants to develop a data loss prevention (DLP) program. The FIRST step should be to implement:

Options

  • Asecurity awareness training
  • Baccess controls
  • Cdata classification
  • Ddata encryption

How the community answered

(61 responses)
  • A
    3% (2)
  • B
    3% (2)
  • C
    92% (56)
  • D
    2% (1)

Explanation

Data classification must come first because you cannot protect data you haven't identified and categorized - without knowing what data is sensitive, critical, or public, any subsequent controls are applied blindly and inconsistently.

Why the distractors are wrong:

  • A (Security awareness training): Training employees on handling data is valuable, but meaningless without first defining what data requires protection and why.
  • B (Access controls): You can't determine who should access data until you know what the data is and how sensitive it is - classification drives access decisions.
  • D (Data encryption): Encrypting everything is costly and impractical; classification tells you which data warrants encryption.

Memory tip: Think of DLP as building a house - classification is the blueprint. You wouldn't hire electricians (access controls), buy locks (encryption), or train workers (awareness) before you have a plan showing what rooms exist and what's in them.

Topics

#Data Loss Prevention#Data Classification#Security Program Development

Community Discussion

No community discussion yet for this question.

Full CISA Practice