CAS-002 · Question #166
In an effort to reduce internal email administration costs, a company is determining whether to outsource its email to a managed service provider that provides email, spam, and malware protection…
The correct answer is C. Enable data loss protection to minimize emailing PII and confidential data. Data Loss Prevention is the most direct technical control to prevent intellectual property from being disclosed through email when using a third-party managed email provider.
Question
In an effort to reduce internal email administration costs, a company is determining whether to outsource its email to a managed service provider that provides email, spam, and malware protection. The security manager is asked to provide input regarding any security implications of this change. Which of the following BEST addresses risks associated with disclosure of intellectual property?
Options
- ARequire the managed service provider to implement additional data separation.
- BRequire encrypted communications when accessing email.
- CEnable data loss protection to minimize emailing PII and confidential data.
- DEstablish an acceptable use policy and incident response policy.
How the community answered
(28 responses)- A7% (2)
- B18% (5)
- C71% (20)
- D4% (1)
Why each option
Data Loss Prevention is the most direct technical control to prevent intellectual property from being disclosed through email when using a third-party managed email provider.
Data separation by the MSP addresses isolation between different MSP tenants but does not prevent employees from emailing intellectual property to external recipients.
Encrypting communications protects data in transit from eavesdropping but does not prevent an authorized user from sending sensitive intellectual property outbound via email.
DLP technology inspects outbound email content and attachments for sensitive data patterns - such as confidential documents, trade secrets, or PII - and can block or quarantine messages before they leave the organization's control. This directly addresses the risk that employees might inadvertently or intentionally email intellectual property through a provider that has broader visibility into message content than an internal system.
An acceptable use policy and incident response policy are administrative controls that establish rules and procedures but do not technically enforce or prevent data disclosure in real time.
Concept tested: Data loss prevention for intellectual property protection in managed email
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp
Topics
Community Discussion
No community discussion yet for this question.