CAS-003 · Question #834
A security engineer at a company is designing a system to mitigate recent setbacks caused by competitors that are beating the company to market with new products. Several of the products incorporate…
The correct answer is A. DLP. When proprietary intellectual property is being stolen and appearing in competitor products, Data Loss Prevention (DLP) is the targeted control that monitors and blocks unauthorized exfiltration of sensitive data.
Question
A security engineer at a company is designing a system to mitigate recent setbacks caused by competitors that are beating the company to market with new products. Several of the products incorporate proprietary enhancements developed by the engineer’s company. The network already includes a SIEM and a NIPS and requires 2FA for all user access. Which of the following systems should the engineer consider NEXT to mitigate the associated risks?
Options
- ADLP
- BMail gateway
- CData flow enforcement
- DUTM
How the community answered
(56 responses)- A66% (37)
- B11% (6)
- C18% (10)
- D5% (3)
Why each option
When proprietary intellectual property is being stolen and appearing in competitor products, Data Loss Prevention (DLP) is the targeted control that monitors and blocks unauthorized exfiltration of sensitive data.
DLP solutions inspect content in motion, at rest, and in use to identify and block the unauthorized transfer of proprietary data - including source code, designs, and trade secrets. Because the scenario involves competitors obtaining proprietary enhancements developed internally, DLP directly addresses the insider or network-based data exfiltration path that is enabling this loss, complementing the existing SIEM and NIPS that do not have content-aware data exfiltration controls.
A mail gateway filters email threats and spam but covers only one exfiltration channel and lacks the content-inspection depth needed to detect and block exfiltration of proprietary data across all egress paths.
Data flow enforcement is a broader architectural concept rather than a specific deployable system, and without a DLP tool implementing it, it does not provide the automated detection and blocking needed to stop ongoing IP theft.
A UTM (Unified Threat Management) device combines perimeter controls like firewall, IPS, and antivirus but does not perform content-aware inspection of outbound data for proprietary information, making it ineffective against intellectual property exfiltration.
Concept tested: DLP deployment to prevent intellectual property exfiltration
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.