nerdexam
CompTIA

SY0-301 · Question #64

Which of the following security concepts would Sara, the security administrator, use to mitigate the risk of data loss?

The correct answer is B. Clean desk policy. A clean desk policy is a physical/administrative security control requiring employees to clear their workspaces of sensitive documents, notes, and media when leaving their desks. This directly mitigates the risk of data loss or unauthorized disclosure by ensuring sensitive…

Security program management and oversight

Question

Which of the following security concepts would Sara, the security administrator, use to mitigate the risk of data loss?

Options

  • ARecord time offset
  • BClean desk policy
  • CCloud computing
  • DRoutine log review

How the community answered

(63 responses)
  • A
    2% (1)
  • B
    89% (56)
  • C
    3% (2)
  • D
    6% (4)

Explanation

A clean desk policy is a physical/administrative security control requiring employees to clear their workspaces of sensitive documents, notes, and media when leaving their desks. This directly mitigates the risk of data loss or unauthorized disclosure by ensuring sensitive information is not left visible or accessible to passers-by, cleaners, or other unauthorized individuals. Record time offset relates to synchronizing log timestamps, which aids forensic investigations but does not prevent data loss. Cloud computing is a delivery model, not a loss-prevention control. Routine log review is a detective control that identifies suspicious activity after the fact rather than preventing physical data exposure.

Topics

#clean desk policy#data loss prevention#administrative controls#physical security

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice