nerdexam
CompTIA

SY0-501 · Question #486

A company has a data classification system with definitions for "Private" and "Public". the company's security policy outlines how data should be protected based on type. The company recently added…

The correct answer is C. Better data classification. Adding a new data type like "Proprietary" refines a company's existing data classification system, allowing for more granular categorization and protection policies.

Submitted by rohit_dlh· Mar 4, 2026Security program management and oversight

Question

A company has a data classification system with definitions for "Private" and "Public". the company's security policy outlines how data should be protected based on type. The company recently added data type "Proprietary". Which of the following is the MOST likely reason the company added this data type?

Options

  • AReduced cost
  • BMore searchable data
  • CBetter data classification
  • DExpanded authority of the privacy officer

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    13% (2)
  • C
    75% (12)
  • D
    6% (1)

Why each option

Adding a new data type like "Proprietary" refines a company's existing data classification system, allowing for more granular categorization and protection policies.

AReduced cost

Adding a new data classification category typically introduces more complexity and potentially more stringent controls, which is unlikely to lead to reduced operational or security costs.

BMore searchable data

Data classification primarily focuses on categorizing data for protection and policy enforcement, not directly on enhancing its searchability, which is usually addressed by indexing or metadata solutions.

CBetter data classificationCorrect

Adding a new, more specific data type such as "Proprietary" allows the company to establish finer granularity in categorizing its information. This enables the application of more precise security controls and handling policies tailored to this distinct category of sensitive data, leading to a more robust and effective overall data classification system.

DExpanded authority of the privacy officer

While a privacy officer is involved in data governance, the act of adding a new data classification type is a policy and technical decision for data protection, not an inherent expansion of an individual's organizational authority.

Concept tested: Data classification and protection policy refinement

Source: https://learn.microsoft.com/en-us/purview/information-protection-sensitivity-labels

Topics

#data classification#security policy#data governance#proprietary data

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice