CAS-001 · Question #136
In an effort to reduce internal email administration costs, a company is determining whether to outsource its email to a managed service provider that provides email, spam, and malware protection…
The correct answer is C. Enable data loss protection to minimize emailing PII and confidential data. Data Loss Prevention (DLP) directly addresses the risk of intellectual property disclosure by monitoring and blocking outbound emails that contain sensitive content such as PII, trade secrets, or confidential business data. DLP is the technical control specifically designed to…
Question
In an effort to reduce internal email administration costs, a company is determining whether to outsource its email to a managed service provider that provides email, spam, and malware protection. The security manager is asked to provide input regarding any security implications of this change. Which of the following BEST addresses risks associated with disclosure of intellectual property?
Options
- ARequire the managed service provider to implement additional data separation.
- BRequire encrypted communications when accessing email.
- CEnable data loss protection to minimize emailing PII and confidential data.
- DEstablish an acceptable use policy and incident response policy.
How the community answered
(34 responses)- A12% (4)
- B3% (1)
- C82% (28)
- D3% (1)
Explanation
Data Loss Prevention (DLP) directly addresses the risk of intellectual property disclosure by monitoring and blocking outbound emails that contain sensitive content such as PII, trade secrets, or confidential business data. DLP is the technical control specifically designed to prevent unauthorized transmission of sensitive information. Option A (data separation) addresses multi-tenancy isolation at the provider but does not prevent employees from sending sensitive data out. Option B (encrypted communications) protects data in transit from interception but does not prevent authorized users from emailing confidential data to unintended recipients. Option D (acceptable use and incident response policies) are administrative controls that are necessary but insufficient on their own to prevent IP disclosure.
Topics
Community Discussion
No community discussion yet for this question.