nerdexam
Isaca

CGEIT · Question #295

To minimize the potential mishandling of customer personal information in a system located in a country with strict privacy regulations which of the following is the BEST action to take?

The correct answer is C. Implement data loss prevention (DLP). To minimize mishandling of customer personal information under strict privacy regulations, implementing data loss prevention (DLP) is the most direct and effective technical control. DLP systems actively monitor, detect, and block sensitive data from leaving defined boundaries, t

Submitted by salim_om· Apr 18, 2026Risk Optimization

Question

To minimize the potential mishandling of customer personal information in a system located in a country with strict privacy regulations which of the following is the BEST action to take?

Options

  • AUpdate the information architecture
  • BRevise the IT strategic plan
  • CImplement data loss prevention (DLP)
  • DEstablish new IT key risk indicators (KRIs)

How the community answered

(21 responses)
  • A
    10% (2)
  • B
    5% (1)
  • C
    81% (17)
  • D
    5% (1)

Why each option

To minimize mishandling of customer personal information under strict privacy regulations, implementing data loss prevention (DLP) is the most direct and effective technical control. DLP systems actively monitor, detect, and block sensitive data from leaving defined boundaries, thus directly addressing potential mishandling and leakage.

AUpdate the information architecture

Updating the information architecture might redesign data flows but does not inherently prevent data mishandling without specific controls like DLP.

BRevise the IT strategic plan

Revising the IT strategic plan is a high-level organizational task that sets future direction but does not provide an immediate, specific technical control for data protection.

CImplement data loss prevention (DLP)Correct

Data Loss Prevention (DLP) solutions are designed to identify, monitor, and protect sensitive data, such as customer personal information, from unauthorized use, transfer, or leakage. By enforcing policies, DLP actively prevents data from being mishandled or exfiltrated, ensuring compliance with strict privacy regulations.

DEstablish new IT key risk indicators (KRIs)

Establishing new IT key risk indicators (KRIs) helps monitor risk levels but does not prevent data mishandling directly; it only indicates when risk thresholds are met.

Concept tested: Data Loss Prevention (DLP)

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide

Topics

#Data Loss Prevention (DLP)#Data Privacy#Risk Mitigation#Information Security Controls

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice