A compliance lead scopes a statewide privacy policy to every configuration item in the CMDB, including printers and unused lab PCs. What is the main problem with that entity scope?
Select an answer to reveal the explanation.
Short Explanation
Think of watering every plant on the block when only the vegetable garden needs it — you drown the roses and still miss the tomatoes. If privacy controls hit every printer and forgotten lab PC, testers drown in noise and never prove the systems that actually touch personal data. Scope entities to where the obligation lives.
Full Explanation
Entity scope should reflect where a policy or obligation meaningfully applies. Including every CMDB CI forces compliance testing on objects that rarely process personal data, which dilutes evidence quality and wastes attestation effort. Implementers define scoped populations—such as applications and services that store or process PII—so control tests stay relevant. Over-broad inclusion is a common anti-pattern that produces false confidence through volume rather than coverage of real exposure.