nerdexam
Isaca

CISA · Question #8

Which of the following should be the FIRST step when developing a data loss prevention (DLP) solution for a large organization?

The correct answer is C. Conduct a data inventory and classification exercise.. The initial step in developing a DLP solution for a large organization must be to conduct a comprehensive data inventory and classification exercise to identify where sensitive data resides and its level of criticality.

Submitted by daniela_cl· Apr 18, 2026Protection of Information Assets

Question

Which of the following should be the FIRST step when developing a data loss prevention (DLP) solution for a large organization?

Options

  • ACreate the DLP policies and templates.
  • BConduct a threat analysis against sensitive data usage.
  • CConduct a data inventory and classification exercise.
  • DIdentify approved data workflows across the enterprise.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    72% (18)
  • D
    16% (4)

Why each option

The initial step in developing a DLP solution for a large organization must be to conduct a comprehensive data inventory and classification exercise to identify where sensitive data resides and its level of criticality.

ACreate the DLP policies and templates.

Creating DLP policies and templates prematurely without knowing what data needs protection will result in ineffective or overly broad policies.

BConduct a threat analysis against sensitive data usage.

Conducting a threat analysis against sensitive data usage requires prior knowledge of what sensitive data exists and where it is used, which comes from data inventory and classification.

CConduct a data inventory and classification exercise.Correct

Before any policies can be effectively designed or threats analyzed, an organization must first understand what data it possesses, where it is stored, and how sensitive it is. Data inventory and classification provide the foundational knowledge necessary to define what needs protecting and guide the scope and focus of DLP policies.

DIdentify approved data workflows across the enterprise.

Identifying approved data workflows is an important subsequent step, but it cannot be done effectively without first understanding the landscape of the data itself through inventory and classification.

Concept tested: Data Loss Prevention (DLP) implementation steps

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide

Topics

#DLP Implementation#Data Classification#Data Inventory#Information Asset Protection

Community Discussion

No community discussion yet for this question.

Full CISA Practice