100-160 exam dumps

100-160 practice question 207 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 207

Select 3

You are conducting a security assessment of an IT system for a healthcare organization. During the process, you notice that certain files containing patient records are classified as 'Public' instead of 'Confidential.' Which of the following actions should you take to ensure compliance with data classification policies?

  1. A

    Notify the organization's data owner about the misclassification and recommend reclassification of the files.

  2. B

    Immediately delete the files to prevent unauthorized access to sensitive information.

  3. C

    Recommend implementing access controls to restrict access to the files until they are reclassified.

  4. D

    Document the misclassification issue and include it in your final assessment report.

  5. E

    Reclassify the files yourself to 'Confidential' to quickly resolve the issue.

Show answer and explanation

Correct answers: A, C, D

Explanation

When dealing with data misclassification, it is important to follow established procedures to ensure sensitive information is protected and compliance requirements are met. Notifying the data owner, implementing temporary security measures like access controls, and documenting the issue for follow-up are all critical steps. Taking unauthorized actions, such as deleting or reclassifying data, can lead to additional security, compliance, or operational risks.

  • A. Correct.

    Correct. Notifying the data owner ensures the appropriate authority is aware of the issue and can take the necessary steps to reclassify the files according to the organization's data classification policy.

  • B. Incorrect.

    Incorrect. Deleting the files without proper authorization could result in data loss and is not an appropriate response to a misclassification issue.

  • C. Correct.

    Correct. Implementing access controls is a necessary protective measure to prevent unauthorized access to sensitive information while the issue is being resolved.

  • D. Correct.

    Correct. Documenting the issue in the final assessment report ensures that it is formally recorded and can be addressed during remediation efforts.

  • E. Incorrect.

    Incorrect. Reclassifying the files yourself without proper authorization violates standard protocols for data management and security.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam