CompTIA CASP+ (CAS-003) — Question 129

A security analyst is classifying data based on input from data owners and other stakeholders. The analyst has identified three data types:
1. Financially sensitive data
2. Project data
3. Sensitive project data
The analyst proposes that the data be protected in two major groups, with further access control separating the financially sensitive data from the sensitive project data. The normal project data will be stored in a separate, less secure location. Some stakeholders are concerned about the recommended approach and insist that commingling data from different sensitive projects would leave them vulnerable to industrial espionage.
Which of the following is the BEST course of action for the analyst to recommend?

Answer options

Correct answer: B

Explanation

The best course of action is to meet with the affected stakeholders to understand their concerns and determine the necessary security controls to mitigate the risks. This approach fosters communication and collaboration, ensuring that stakeholder worries are addressed. The other options, while potentially useful, do not directly involve engaging stakeholders or may not effectively address the specific concerns about industrial espionage.