nerdexam
CompTIA

CV0-002 · Question #496

The risk and compliance team mandates that all PII should be sent via secure and encrypted channels via webmail. As the SaaS administrator, which of the following is the BEST method for implementing d

The correct answer is C. Data classification matrix. To implement the risk and compliance mandate for securing PII sent via webmail, a SaaS administrator should first establish a data classification matrix. This matrix provides the framework to identify PII and subsequently apply appropriate technical controls like encryption.

Security

Question

The risk and compliance team mandates that all PII should be sent via secure and encrypted channels via webmail. As the SaaS administrator, which of the following is the BEST method for implementing data governance?

Options

  • AData custodian register
  • BInformation usage policy
  • CData classification matrix
  • DFileshare permissions

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    76% (13)
  • D
    12% (2)

Why each option

To implement the risk and compliance mandate for securing PII sent via webmail, a SaaS administrator should first establish a data classification matrix. This matrix provides the framework to identify PII and subsequently apply appropriate technical controls like encryption.

AData custodian register

A data custodian register identifies individuals responsible for data assets but does not define how the data itself should be handled, secured, or communicated.

BInformation usage policy

An information usage policy defines rules for data handling, but it relies on an underlying data classification to determine which policies apply to specific types of data, and it's a procedural document rather than a direct implementation method for technical security.

CData classification matrixCorrect

A data classification matrix is the fundamental component for effective data governance, as it systematically categorizes information based on sensitivity, regulatory requirements, and business impact. By classifying data, including PII, the organization can then consistently implement and automate the necessary security controls, such as ensuring PII is sent via secure and encrypted channels through webmail.

DFileshare permissions

Fileshare permissions control access to files stored on a fileshare, which is not directly relevant to mandating secure and encrypted transmission of PII via webmail.

Concept tested: Data governance, data classification, and PII protection

Source: https://learn.microsoft.com/en-us/purview/data-classification-overview

Topics

#Data governance#PII protection#Data classification#Compliance

Community Discussion

No community discussion yet for this question.

Full CV0-002 Practice