CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 293


An organization has developed a way for customers to share information from their wearable devices with each other. Unfortunately, the users were not informed as to what information collected would be shared. What technical controls should be put in place to remedy the privacy issue while still trying to accomplish the organization's business goals?

Show Answer
Correct Answer: C

To address the privacy issue, the best approach is to default the user to not share any information. This technical control ensures that no data is shared without the user's explicit consent, thereby respecting their privacy. By defaulting to no sharing, users retain control over their personal information and can opt-in to share data if they choose to do so. This method effectively balances the organization's business goals with user privacy needs.

Discussion

12 comments
Sign in to comment
CL8282Option: C
Oct 18, 2024

C: They are asking about "Technical" controls

UaedragonOption: D
May 15, 2023

The users are not informed in this scenario, so first the users have to be informed A. Organization cannot decide on behalf of user, can they ? B. Functionality has been developed C. Possibly right as well D. Possibly right as well

Hava_2013
May 16, 2023

The given answer is the best choice since it asks for What technical controls should be put in place, the only technical control here is "C"

629f731Option: C
Jul 13, 2024

The key is "technical". It is asking for technical controls soi i go for C

klarakOption: C
Nov 8, 2024

The key term is "technical control"

franbarpro
Apr 25, 2023

Let's have them not share info with eath other.

DJOEKOption: C
Jul 12, 2023

It is asking for technical controls soi i go for C out of C and D

omarin25Option: C
Jul 25, 2023

Stop sharing until you implement policy

jackdryan
Nov 13, 2023

C is correct

bherto39Option: D
Mar 26, 2024

D. Inform the user of the sharing feature changes after implemented. To remedy the privacy issue while still accomplishing the organization's business goals, it's essential to inform users of the changes and obtain their informed consent regarding what information will be shared from their wearable devices. Transparency and user consent are important principles in data privacy. Users should be given clear information about the data sharing and should have the option to opt in or opt out of sharing as per their preferences. This approach respects user privacy and allows them to make informed decisions about sharing their data.

InclusiveSTEAM
Apr 17, 2024

Option C: Setting sharing to off by default gives users control over their data and ensures nothing is shared inadvertently. D option -Notifying users of the changes is also imperative for transparency and consent, is secondary.

Soleandheel
Jun 14, 2024

C. Default the user to not share any information.......I went with C. instead of D. Inform the user of the sharing feature changes after implemented... because it is common klnowledge and a best practice to always inform users prior to implementing a change instead of after implementation especially when it has to deal with their data and privacy. C. Default the user to not share any information is a more reasonable answer to me.

BigITGuyOption: C
Apr 2, 2025

Not D. Informing users after changes is too late and violates transparency principles. Users must be informed before data is shared.