700-280 · Question #55
Which option describes when a DLP incident occurs?
The correct answer is A. when potentially sensitive content appears in a message. A DLP (Data Loss Prevention) incident is triggered whenever potentially sensitive content is detected in a message, regardless of whether that content is confirmed to be truly sensitive or harmful - the system flags it for review based on pattern matching and policy rules. Why…
Question
Which option describes when a DLP incident occurs?
Options
- Awhen potentially sensitive content appears in a message
- Bwhen one or more users receive classified information via email
- Cwhen a system administrator fails to enable the DLP feature key
- Dif a message contains a number that looks like a credit card number
How the community answered
(22 responses)- A91% (20)
- B5% (1)
- C5% (1)
Explanation
A DLP (Data Loss Prevention) incident is triggered whenever potentially sensitive content is detected in a message, regardless of whether that content is confirmed to be truly sensitive or harmful - the system flags it for review based on pattern matching and policy rules.
Why the distractors are wrong:
- B is wrong because DLP incidents aren't limited to email, nor do they require the content to be classified - they occur across multiple channels at the point of detection, not delivery.
- C is wrong because a DLP incident is a content-based event, not an administrative configuration failure; failing to enable DLP means incidents simply won't be detected, not that one has occurred.
- D is a partial truth that makes it a tempting trap - a credit card number pattern would trigger a DLP incident, but it's too narrow; DLP policies cover many content types (SSNs, health data, keywords, etc.), so D describes one example, not the definition.
Memory tip: Think of DLP as a smoke detector - it triggers on the presence of smoke (potentially sensitive content), not on confirmation that a fire (actual breach) occurred. "Potentially" is the key word in option A.
Topics
Community Discussion
No community discussion yet for this question.