nerdexam
CompTIA

CAS-002 · Question #600

An internal employee has sold a copy of the production customer database that was being used for upgrade testing to outside parties via HTTP file upload. The Chief Information Officer (CIO) has…

The correct answer is B. Data loss prevention. Data Loss Prevention (DLP) is the most effective control for detecting and blocking unauthorized exfiltration of sensitive data such as a customer database uploaded over HTTP.

Enterprise Security

Question

An internal employee has sold a copy of the production customer database that was being used for upgrade testing to outside parties via HTTP file upload. The Chief Information Officer (CIO) has resigned and the Chief Executive Officer (CEO) has tasked the incoming CIO with putting effective controls in place to help prevent this from occurring again in the future. Which of the following controls is the MOST effective in preventing this threat from re-occurring?

Options

  • ANetwork-based intrusion prevention system
  • BData loss prevention
  • CHost-based intrusion detection system
  • DWeb application firewall

How the community answered

(47 responses)
  • A
    9% (4)
  • B
    83% (39)
  • C
    6% (3)
  • D
    2% (1)

Why each option

Data Loss Prevention (DLP) is the most effective control for detecting and blocking unauthorized exfiltration of sensitive data such as a customer database uploaded over HTTP.

ANetwork-based intrusion prevention system

A network-based IPS detects and blocks known attack signatures and anomalous traffic, but it is not designed to identify and stop authorized users from intentionally uploading sensitive files.

BData loss preventionCorrect

DLP solutions inspect outbound network traffic for sensitive content patterns - such as large database exports or PII - and can block or alert on unauthorized transfers regardless of protocol, including HTTP uploads. DLP directly addresses the insider threat scenario by monitoring and controlling data movement at the network and endpoint level. It is specifically designed to prevent the type of deliberate data exfiltration described in this scenario.

CHost-based intrusion detection system

A host-based IDS monitors system activity for signs of compromise but does not prevent a legitimate user from deliberately copying and uploading data.

DWeb application firewall

A web application firewall protects web applications from external attacks such as SQL injection and XSS, not outbound data exfiltration by internal users.

Concept tested: Data loss prevention for insider threat exfiltration

Source: https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp

Topics

#data loss prevention#insider threat#data exfiltration#DLP

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice