nerdexam
CompTIA

CAS-002 · Question #166

In an effort to reduce internal email administration costs, a company is determining whether to outsource its email to a managed service provider that provides email, spam, and malware protection…

The correct answer is C. Enable data loss protection to minimize emailing PII and confidential data. Data Loss Prevention is the most direct technical control to prevent intellectual property from being disclosed through email when using a third-party managed email provider.

Enterprise Security

Question

In an effort to reduce internal email administration costs, a company is determining whether to outsource its email to a managed service provider that provides email, spam, and malware protection. The security manager is asked to provide input regarding any security implications of this change. Which of the following BEST addresses risks associated with disclosure of intellectual property?

Options

  • ARequire the managed service provider to implement additional data separation.
  • BRequire encrypted communications when accessing email.
  • CEnable data loss protection to minimize emailing PII and confidential data.
  • DEstablish an acceptable use policy and incident response policy.

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    18% (5)
  • C
    71% (20)
  • D
    4% (1)

Why each option

Data Loss Prevention is the most direct technical control to prevent intellectual property from being disclosed through email when using a third-party managed email provider.

ARequire the managed service provider to implement additional data separation.

Data separation by the MSP addresses isolation between different MSP tenants but does not prevent employees from emailing intellectual property to external recipients.

BRequire encrypted communications when accessing email.

Encrypting communications protects data in transit from eavesdropping but does not prevent an authorized user from sending sensitive intellectual property outbound via email.

CEnable data loss protection to minimize emailing PII and confidential data.Correct

DLP technology inspects outbound email content and attachments for sensitive data patterns - such as confidential documents, trade secrets, or PII - and can block or quarantine messages before they leave the organization's control. This directly addresses the risk that employees might inadvertently or intentionally email intellectual property through a provider that has broader visibility into message content than an internal system.

DEstablish an acceptable use policy and incident response policy.

An acceptable use policy and incident response policy are administrative controls that establish rules and procedures but do not technically enforce or prevent data disclosure in real time.

Concept tested: Data loss prevention for intellectual property protection in managed email

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp

Topics

#data loss prevention#managed service provider risk#intellectual property#cloud email security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice