nerdexam
CompTIA

CAS-001 · Question #266

The Chief Information Officer (CIO) comes to the security manager and asks what can be done to reduce the potential of sensitive data being emailed out of the company. Which of the following is an…

The correct answer is B. Sanitize outgoing content. Sanitizing outgoing content is an active, technical control that inspects and removes or blocks sensitive data before it leaves the organization - this is the core function of a Data Loss Prevention (DLP) system applied to email. It actively intervenes in the data flow. Digital…

Enterprise Security

Question

The Chief Information Officer (CIO) comes to the security manager and asks what can be done to reduce the potential of sensitive data being emailed out of the company. Which of the following is an active security measure to protect against this threat?

Options

  • ARequire a digital signature on all outgoing emails.
  • BSanitize outgoing content.
  • CImplement a data classification policy.
  • DImplement a SPAM filter.

How the community answered

(28 responses)
  • A
    14% (4)
  • B
    75% (21)
  • C
    4% (1)
  • D
    7% (2)

Explanation

Sanitizing outgoing content is an active, technical control that inspects and removes or blocks sensitive data before it leaves the organization - this is the core function of a Data Loss Prevention (DLP) system applied to email. It actively intervenes in the data flow. Digital signatures (A) verify sender identity but do nothing to prevent sensitive content from being included. A data classification policy (C) is an administrative control - it defines what is sensitive but doesn't technically prevent it from being emailed. A SPAM filter (D) targets inbound unwanted email and has no effect on outbound data leakage.

Topics

#DLP#data exfiltration#content filtering#email security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice