SY0-701 Question 283
Single answerClassificationA healthcare organization is implementing a new data handling standard after discovering that staff have been emailing patient billing spreadsheets to external partners without consistent protection. The security manager wants a classification scheme that ensures the strongest controls are applied to data that would cause the most harm if disclosed, while allowing low-risk information to be shared more easily. Which action should the organization take FIRST to build an effective classification program?
- A
Classify data based on the potential business, legal, and privacy impact of unauthorized disclosure, then map handling requirements to each classification level
- B
Encrypt all files by default and postpone data classification until the organization finishes deploying a new email gateway
- C
Allow each department to create its own labels and handling rules so classifications match local workflows
- D
Classify data only by file type, such as spreadsheets, PDFs, and emails, because those formats determine the required security controls
Show answer and explanation
Correct answer: A
Explanation
The best first step in a classification program is to define classification levels according to the potential impact of unauthorized disclosure, modification, or loss of the data, and then assign handling requirements to each level. This aligns with common information security governance practices and frameworks such as NIST guidance on information categorization and data handling, where organizations identify sensitive or regulated information and apply appropriate protections based on risk and compliance obligations. In this scenario, healthcare data may be subject to HIPAA requirements, so regulated information should be clearly identified and handled according to stricter controls. Classification should be enterprise-wide, content-based, and tied to policy-driven safeguards such as labeling, encryption, transmission restrictions, access control, and retention.
- A. Correct.
Correct. An effective data classification program starts by identifying data sensitivity and the impact to the organization, customers, and regulatory obligations if the data is improperly disclosed, altered, or lost. In this scenario, patient billing data likely includes protected health information (PHI), so classification should be driven by business and compliance impact, not convenience. Once classification levels are defined, the organization can map handling requirements such as encryption, access controls, retention, transmission rules, and sharing restrictions to each level.
- B. Incorrect.
Incorrect. Encryption is an important control, but it is not a substitute for classification. Without first identifying which data is most sensitive and what handling rules apply, the organization may misapply controls, overlook regulated data, or fail to define acceptable sharing practices. Security+ expects candidates to understand that classification drives control selection rather than the other way around.
- C. Incorrect.
Incorrect. Letting each department independently define labels and handling requirements usually creates inconsistent classifications, confusion, and enforcement gaps across the enterprise. While departments may help identify business context, the classification framework should be centrally governed so data receives consistent protection regardless of where it is stored or who uses it.
- D. Incorrect.
Incorrect. File type does not determine sensitivity. A spreadsheet could contain public marketing data or highly regulated patient information. Classification should be based on the content's value and sensitivity, along with legal, contractual, and operational impact. Choosing controls based only on format is a common mistake because it ignores the actual risk presented by the information.