nerdexam
CompTIA

CAS-001 · Question #205

An internal employee has sold a copy of the production customer database that was being used for upgrade testing to outside parties via HTTP file upload. The Chief Information Officer (CIO) has…

The correct answer is B. Data loss prevention. Data Loss Prevention (DLP) is specifically designed to detect and block the unauthorized transmission of sensitive data outside the organization. A DLP solution monitors network traffic (including HTTP uploads), inspects content for patterns matching sensitive data (e.g…

Enterprise Security

Question

An internal employee has sold a copy of the production customer database that was being used for upgrade testing to outside parties via HTTP file upload. The Chief Information Officer (CIO) has resigned and the Chief Executive Officer (CEO) has tasked the incoming CIO with putting effective controls in place to help prevent this from occurring again in the future. Which of the following controls is the MOST effective in preventing this threat from re-occurring?

Options

  • ANetwork-based intrusion prevention system
  • BData loss prevention
  • CHost-based intrusion detection system
  • DWeb application firewall

How the community answered

(39 responses)
  • A
    18% (7)
  • B
    72% (28)
  • C
    8% (3)
  • D
    3% (1)

Explanation

Data Loss Prevention (DLP) is specifically designed to detect and block the unauthorized transmission of sensitive data outside the organization. A DLP solution monitors network traffic (including HTTP uploads), inspects content for patterns matching sensitive data (e.g., customer records, PII, credit card numbers), and can block or alert on exfiltration attempts in real time. A Network IPS detects/blocks known attack signatures but is not tuned to recognize data exfiltration by legitimate insiders. A HIDS only detects suspicious activity on the host after the fact. A Web Application Firewall protects web apps from external attacks, not insider data theft. DLP directly targets the threat vector described.

Topics

#insider threat#data loss prevention#data exfiltration#database security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice