Practice Question
You’re consulting for a healthcare organization that stores patient records in a hybrid cloud environment. The data is classified as "Highly Confidential." A developer in the team has requested access to production data to troubleshoot issues. The organization lacks a robust data classification enforcement policy. What is the BEST course of action?
A. Allow the developer read-only access under supervision.
B. Mask or anonymize the data before granting limited access.
C. Grant access after requiring the developer to sign a confidentiality agreement.
D. Deny access and escalate the request to the compliance team.
2
16 comments
Fouad Ahmed
6
Practice Question
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by