Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard
A large pharmaceutical company is conducting extensive research and development (R&D) on new drug formulations. This R&D data is highly sensitive, proprietary, and subject to strict intellectual property (IP) protection laws. The cybersecurity architect needs to implement a technical strategy that ensures the integrity and confidentiality of this data throughout its lifecycle, from creation to archiving, and provides strong audit trails for regulatory compliance and IP protection. Which strategy is MOST crucial for this scenario?
- AEstablishing an advanced Data Classification and Protection (DCP) framework with encryption and access controls.
- BUtilizing an advanced Security Information and Event Management (SIEM) system with custom R&D data rules.
- CDeploying a comprehensive Data Loss Prevention (DLP) solution across all data egress points.
- DImplementing a robust Cloud Access Security Broker (CASB) for all cloud services.
Show answer & explanationAnswer & explanation
Correct answer: A. Establishing an advanced Data Classification and Protection (DCP) framework with encryption and access controls.
An advanced Data Classification and Protection (DCP) framework directly addresses the need to categorize sensitive R&D data, apply appropriate encryption and granular access controls throughout its lifecycle, and provide audit trails for IP protection and regulatory compliance.
Why the other options are wrong
- B. SIEM collects logs and detects incidents, but it does not actively classify, encrypt, or enforce access controls on the data itself, nor does it guarantee data integrity across its lifecycle.
- C. DLP primarily prevents data exfiltration, which is a component of data protection, but it does not encompass the full lifecycle management, classification, strong access controls, and integrity assurance needed for highly sensitive R&D data.
- D. CASB focuses on securing cloud service access and usage, but doesn't inherently manage the classification, encryption, and lifecycle protection of data itself across all storage types.
Data Classification and Protection (DCP)
DCP is a framework that categorizes data based on its sensitivity and regulatory requirements, then applies appropriate security controls (encryption, access controls, integrity checks) throughout its lifecycle.
- Identifies and tags sensitive data.
- Enforces granular access policies.
- Applies encryption at rest and in transit.
- Maintains data integrity and audit trails.
Memory trick: DCP is the 'Lab Guardian' for 'Sensitive Research Data'.