Which security approach will BEST minimize Personally Identifiable Information (PII) loss from a data breach?
Correct Answer: B
The best security approach to minimize PII loss from a data breach is to limit the collection of individuals' confidential data to the minimum necessary for the business purpose. This is based on the principle of data minimization, which is one of the core principles of privacy by design. By collecting less PII, the organization reduces the amount of data that could be exposed or compromised in a data breach, and thus lowers the potential impact and liability. The other options are not the best security approach, but rather complementary or reactive measures. A strong breach notification process is important to inform the affected individuals and authorities about the data breach, but it does not prevent or minimize the loss of PII. End-to-end data encryption for data in transit is a good practice to protect the confidentiality and integrity of data, but it does not address the data at rest or in use, and it may not prevent unauthorized access if the encryption keys are compromised. Continuous monitoring of potential vulnerabilities is a proactive measure to identify and remediate security weaknesses, but it does not eliminate the possibility of a data breach, and it does not reduce the amount of PII collected or stored. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 3, p. 114; Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 5, p. 289; CISSP practice exam questions and answers, Question 6.