nerdexam
CompTIA

CAS-003 · Question #202

A large bank deployed a DLP solution to detect and block customer and credit card data from leaving the organization via email. A disgruntled employee was able to successfully exfiltrate data…

The correct answer is A. The product does not understand how to decode embedded objects. C. The process of embedding an object obfuscates the data. Two factors allowed the exfiltration to bypass the DLP solution. First (A), many DLP products are designed to inspect known file types and their native content, but they may lack the ability to parse, extract, and inspect objects that are embedded within a foreign file format…

Enterprise Security Operations

Question

A large bank deployed a DLP solution to detect and block customer and credit card data from leaving the organization via email. A disgruntled employee was able to successfully exfiltrate data through the corporate email gateway by embedding a word processing document containing sensitive data as an object in a CAD file. Which of the following BEST explains why it was not detected and blocked by the DLP solution? (Select TWO).

Options

  • AThe product does not understand how to decode embedded objects.
  • BThe embedding of objects in other documents enables document encryption by default.
  • CThe process of embedding an object obfuscates the data.
  • DThe mail client used to send the email is not compatible with the DLP product.
  • EThe DLP product cannot scan multiple email attachments at the same time.

How the community answered

(40 responses)
  • A
    68% (27)
  • B
    5% (2)
  • D
    8% (3)
  • E
    20% (8)

Explanation

Two factors allowed the exfiltration to bypass the DLP solution. First (A), many DLP products are designed to inspect known file types and their native content, but they may lack the ability to parse, extract, and inspect objects that are embedded within a foreign file format. A Word document embedded as an OLE object inside a CAD file is a container-within-a-container scenario the DLP engine may not recognize or decode. Second (C), embedding the sensitive document inside the CAD file effectively obfuscates the data: the DLP engine sees a CAD file and does not find raw credit card numbers or customer data patterns in the CAD format's expected fields, so no policy is triggered. Option B is false - embedding an object does not automatically encrypt it. Options D and E are not supported by the scenario and represent unrelated failure modes.

Topics

#DLP bypass#data exfiltration#embedded objects#email security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice