Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium

A public sector organization is implementing a new data classification scheme to comply with government regulations regarding sensitive data handling. The cybersecurity architect needs to select a technical strategy that ensures consistent application of these classifications across various data repositories (databases, file shares, cloud storage) and enforces appropriate access controls. Which approach is most suitable?

  1. ARelying on network segmentation to isolate sensitive data, without granular classification.
  2. BManually tagging all data files and database entries based on user discretion.
  3. CEncrypting all data uniformly across the organization, regardless of its classification level.
  4. DImplementing an automated data discovery and classification tool that integrates with data repositories and an Identity Governance and Administration (IGA) solution for policy-based access enforcement.
Show answer & explanation

Correct answer: D. Implementing an automated data discovery and classification tool that integrates with data repositories and an Identity Governance and Administration (IGA) solution for policy-based access enforcement.

Automated data discovery and classification, integrated with an IGA solution, provides consistent application of classification labels and dynamic enforcement of access controls across diverse data repositories, which is crucial for compliance in a public sector organization.

Why the other options are wrong

  • A. Network segmentation is a foundational control but doesn't provide granular data classification or policy-based access enforcement based on the data's sensitivity, which is often required by government regulations.
  • B. Manual tagging is inconsistent, error-prone, and not scalable for a large organization, making it unsuitable for consistent regulatory compliance.
  • C. Uniform encryption is good practice but does not replace data classification for applying appropriate, differentiated controls based on sensitivity or enforce granular access policies.

Automated Data Classification

The use of software tools to automatically identify, categorize, and tag data based on its content, context, and sensitivity, often integrating with existing data protection systems.

  • Ensures consistent application of classification policies across large datasets.
  • Reduces manual effort and human error.
  • Enables dynamic enforcement of security controls based on data sensitivity.

Memory trick: Automated Classification + IGA for Government Data

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions