CompTIA SecurityX (CAS-005) — Question 123
After a leak of important documents, a company decides to implement a data protection program to avoid similar incidents in the future. Which of the following should the company do first?
Answer options
- A. Implement data encryption.
- B. Perform data storage hardening.
- C. Deploy a data loss prevention policy.
- D. Develop data labeling standards.
Correct answer: D
Explanation
Developing data labeling standards is essential as it creates a framework for classifying and managing data based on its sensitivity. This step is crucial before implementing encryption or other protective measures, as it ensures that the data is appropriately identified and categorized. The other options, while important, should follow the establishment of clear labeling standards to be effective.