nerdexam
Cisco

350-201 · Question #80

A security architect is working in a processing center and must implement a DLP solution to detect and prevent any type of copy and paste attempts of sensitive data within unapproved applications…

The correct answer is C. DLP for data in use. Copy-and-paste operations and transfers to removable devices involve data actively being accessed and manipulated by a user, which falls under the DLP 'data in use' category.

Techniques

Question

A security architect is working in a processing center and must implement a DLP solution to detect and prevent any type of copy and paste attempts of sensitive data within unapproved applications and removable devices. Which technical architecture must be used?

Options

  • ADLP for data in motion
  • BDLP for removable data
  • CDLP for data in use
  • DDLP for data at rest

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    91% (41)
  • D
    2% (1)

Why each option

Copy-and-paste operations and transfers to removable devices involve data actively being accessed and manipulated by a user, which falls under the DLP 'data in use' category.

ADLP for data in motion

DLP for data in motion inspects data traversing the network such as email or web uploads, and does not cover local clipboard or removable device interactions.

BDLP for removable data

'DLP for removable data' is not a recognized standard DLP architectural category - removable device control is a function of data in use DLP.

CDLP for data in useCorrect

DLP for data in use monitors and enforces policy on data that is actively being processed, accessed, or manipulated by end users in real time. This includes clipboard operations such as copy and paste, as well as attempts to transfer data to removable storage devices like USB drives. Endpoint DLP agents enforce these controls directly on the workstation where the user interaction occurs.

DDLP for data at rest

DLP for data at rest discovers and protects sensitive data stored in repositories, file shares, and databases, and does not monitor active user interactions like copy and paste.

Concept tested: DLP data in use - endpoint clipboard and removable media control

Source: https://learn.microsoft.com/en-us/purview/endpoint-dlp-learn-about

Topics

#DLP#data in use#endpoint security#data protection

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice