ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a pre-authorization audit you learn that many sensitive reports do not display their classification when printed, increasing the chance they will be mishandled once they leave the office. Which corrective action best satisfies data-marking requirements for visibility of sensitivity and handling instructions?
Enforce file encryption and digital rights management on all sensitive documents without adding any visible classification text.
Configure document templates to automatically add the correct classification label in the header and footer of each page when files are created or exported.
Require staff to store documents only in network folders whose names reflect the data classification level.
Embed an invisible digital watermark that encodes the classification and can be read by forensic tools if needed.
Data marking is intended to place clear, human-readable indicators on information so anyone who encounters it immediately understands its sensitivity and handling constraints. Automatically inserting the appropriate classification banner in the header and footer of every page ensures the label is visible whether the file is viewed on-screen, printed, or detached from its original storage location. Relying only on encryption/DRM, folder names, or invisible watermarks provides protection or traceability but does not meet the core objective of visible labelling that alerts users before they act.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is data marking, and why is it important in information security?
Open an interactive chat with Bash
How does embedding classification in headers and footers enhance security?
Open an interactive chat with Bash
What are the limitations of relying solely on encryption and digital rights management (DRM) for sensitive information?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .