nerdexam
CompTIA

SY0-301 · Question #649

Which of the following policies is implemented in order to minimize data loss or theft?

The correct answer is A. PII handling. A PII (Personally Identifiable Information) handling policy (A) defines how sensitive personal data is collected, stored, transmitted, accessed, and disposed of throughout its lifecycle. By specifying classification levels, encryption requirements, access restrictions, and…

Security program management and oversight

Question

Which of the following policies is implemented in order to minimize data loss or theft?

Options

  • APII handling
  • BPassword policy
  • CChain of custody
  • DZero day exploits

How the community answered

(27 responses)
  • A
    93% (25)
  • B
    4% (1)
  • D
    4% (1)

Explanation

A PII (Personally Identifiable Information) handling policy (A) defines how sensitive personal data is collected, stored, transmitted, accessed, and disposed of throughout its lifecycle. By specifying classification levels, encryption requirements, access restrictions, and disposal procedures, it directly addresses and minimizes the risk of data loss or theft. A password policy (B) governs authentication strength and rotation, which supports access control but does not directly govern data handling. Chain of custody (C) documents the possession and transfer of evidence in forensic or legal contexts - it does not prevent data loss. Zero-day exploits (D) are a category of vulnerability, not a policy; no policy is named after them in this context.

Topics

#PII handling#data loss prevention#policy#data protection

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice