exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 44 discussion

Actual exam question from CompTIA's CS0-002
Question #: 44
Topic #: 1
[All CS0-002 Questions]

An organization is focused on restructuring its data governance programs, and an analyst has been tasked with surveying sensitive data within the organization.
Which of the following is the MOST accurate method for the security analyst to complete this assignment?

  • A. Perform an enterprise-wide discovery scan.
  • B. Consult with an internal data custodian.
  • C. Review enterprise-wide asset inventory.
  • D. Create a survey and distribute it to data owners.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
skibby16
Highly Voted 1 year, 6 months ago
Selected Answer: A
A data governance program is a collection of practices, policies, and procedures that manage, leverage, and protect the data assets of an organization1. It requires changing the workplace culture and adding some software1. To survey sensitive data within the organization, the most accurate method is to perform an enterprise-wide discovery scan that can identify and classify data from various sources and systems2. This way, the analyst can have a comprehensive view of the data landscape and its quality, security, accessibility, and usage. Consulting with an internal data custodian (B) or reviewing enterprise-wide asset inventory © may provide some insights, but not as accurate or complete as a discovery scan. Creating a survey and distributing it to data owners (D) may be time-consuming and unreliable, as data owners may not have the full knowledge or awareness of their data
upvoted 5 times
RyanMccar
1 year, 6 months ago
Not sure where this answer is from but it sounds official and correct
upvoted 1 times
skibby16
1 year, 5 months ago
References: 1: https://www.analytics8.com/blog/8-steps-to-start-your-data-governance-program/ 2: https://solutionsreview.com/data-management/the-best-data-governance-tools-and-software/
upvoted 1 times
...
...
...
Sebatian20
Most Recent 1 year, 5 months ago
Selected Answer: A
Both C and D are relying on the knowledge of a third party - and they could be wrong. B is logical as you actually talk to those who knows about the system but A is the more logical first step.
upvoted 2 times
...
2Fish
2 years, 1 month ago
Selected Answer: D
D. Is the best option here, specifically how it mentions "Data Owners"
upvoted 2 times
uday1985
1 year, 12 months ago
Really? are you giving a survey to a random guy to fill and trust them they answered accurately?
upvoted 7 times
...
...
boletri
2 years, 2 months ago
Selected Answer: D
Data owner—A senior (executive) role with ultimate responsibility for maintaining the confidentiality, integrity, and availability of the information asset. The owner is responsible for labeling the asset (such as determining who should have access and determining the asset's criticality and sensitivity) and ensuring that it is protected with appropriate controls (access control, backup, retention, and so forth). The owner also typically selects a steward and custodian and directs their actions and sets the budget and resource allocation for sufficient controls.
upvoted 2 times
...
tboi
2 years, 4 months ago
I would go with A simply because a survey of "sensitive" data might lead to loss of data confidentiality. A survey also is also a cumbersome task and might be inefficient.
upvoted 3 times
...
Tascjfbosafj
2 years, 6 months ago
Selected Answer: D
It's D
upvoted 2 times
uday1985
1 year, 12 months ago
Really? are you giving a survey to a random guy to fill and trust them they answered accurately?
upvoted 5 times
...
...
arctanx
2 years, 6 months ago
Selected Answer: D
A Data Owner is the person accountable for the classification, protection, use, and quality of one or more data sets within an organization. This responsibility involves activities including, but not limited to, ensuring that: The organization's Data Glossary is comprehensive and agreed upon by all stakeholders. https://blog.satoricyber.com/the-datamasters-data-owners-vs-data-stewards-vs-data-custodians/#:~:text=A%20Data%20Owner%20is%20the,agreed%20upon%20by%20all%20stakeholders
upvoted 1 times
...
SAAVYTECH
2 years, 7 months ago
Selected Answer: D
Data owners are the people who classify the Data and they also set permission to who access it, so they are the only ones who can provide the most accurate information.
upvoted 2 times
...
nonjabusiness
2 years, 7 months ago
Selected Answer: D
Through the process of elimination, D makes the most sense A- Enumerate OS/ports/services/etc, not dealing with data B- Data custodian handles the technical details of the data C- Assets the company owns, though data is an asset this wouldn't be of much use
upvoted 1 times
...
amateurguy
2 years, 7 months ago
Selected Answer: D
D seems correct by process of elimination, none of the other ones are related to sensitive data.
upvoted 1 times
amateurguy
2 years, 7 months ago
Also, if you know what discovery scans and asset inventory is, you would know that they have nothing to do with the actual sensitive data. They have more to do with hardware and software that are being used so A and C are eliminated.
upvoted 1 times
cyberseckid
2 years, 7 months ago
data discovery scan seems related , can you elaborate on it ? https://it.cornell.edu/data-discovery/how-scan-data-discovery
upvoted 1 times
...
...
...
EAart
2 years, 8 months ago
Selected Answer: D
D, as this is the only answer that mentions data ownership.
upvoted 1 times
...
Laudy
2 years, 8 months ago
A Sounds good to me
upvoted 2 times
Joshgip95
2 years, 2 months ago
Can somebody ban this dude?
upvoted 8 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago