nerdexam
CompTIA

CAS-005 · Question #266

An organization recently implemented a new email DLP solution. Emails sent from company email addresses to matching personal email addresses generated a large number of alerts, but the content of…

The correct answer is B. Create an acceptable use policy. An acceptable use policy (AUP) defines what is considered appropriate use of corporate email and prevents unnecessary emails to personal accounts. This helps in reducing false DLP alerts while maintaining compliance.

Submitted by carlos_mx· Mar 6, 2026Governance, Risk, and Compliance

Question

An organization recently implemented a new email DLP solution. Emails sent from company email addresses to matching personal email addresses generated a large number of alerts, but the content of the emails did not include company data. The security team needs to reduce the number of emails sent without blocking all emails to common personal email services. Which of the following should the security team implement first?

Options

  • AAutomatically quarantine outgoing email.
  • BCreate an acceptable use policy.
  • CEnforce email encryption standards.
  • DPerform security awareness training focusing on phishing.

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    80% (35)
  • C
    5% (2)
  • D
    9% (4)

Explanation

An acceptable use policy (AUP) defines what is considered appropriate use of corporate email and prevents unnecessary emails to personal accounts. This helps in reducing false DLP alerts while maintaining compliance.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice