nerdexam
Isaca

CISA · Question #428

When auditing a data loss protection (DLP) program, which of the following should an IS auditor consider as the GREATEST access-related risk?

The correct answer is B. Access to DLP rules. Access to DLP rules represents the greatest risk because whoever controls the rules controls what the DLP system detects and blocks - a malicious insider or attacker with rule-modification access can silently whitelist sensitive data transfers, effectively neutralizing the entire

Submitted by devops_kid· Apr 18, 2026Protection of Information Assets

Question

When auditing a data loss protection (DLP) program, which of the following should an IS auditor consider as the GREATEST access-related risk?

Options

  • AAccess to DLP incidents
  • BAccess to DLP rules
  • CAccess to centralized logging system
  • DAccess to regulatory data

How the community answered

(38 responses)
  • A
    11% (4)
  • B
    66% (25)
  • C
    5% (2)
  • D
    18% (7)

Explanation

Access to DLP rules represents the greatest risk because whoever controls the rules controls what the DLP system detects and blocks - a malicious insider or attacker with rule-modification access can silently whitelist sensitive data transfers, effectively neutralizing the entire program without leaving obvious evidence of tampering.

Why the distractors fall short:

  • A (DLP incidents): Viewing incident logs is a confidentiality concern but doesn't allow someone to bypass the DLP controls themselves.
  • C (Centralized logging): Tampering with logs is serious, but it affects the audit trail after the fact - it doesn't disable the preventive control.
  • D (Regulatory data): This is what DLP exists to protect, not a risk to the DLP program's integrity; unauthorized access here is a data breach outcome, not a program control risk.

Memory tip: Frame it as "who guards the guards?" - the riskiest access is always to the control mechanism itself (the rules), not to the data it monitors or the records it generates.

Topics

#DLP (Data Loss Prevention)#Information Security#Risk Management#IS Auditing

Community Discussion

No community discussion yet for this question.

Full CISA Practice