nerdexam
Isaca

CISA · Question #434

Which of the following is the PRIMARY function of a data loss prevention (DLP) policy when implemented in an organization's DLP solution?

The correct answer is B. To define rules for monitoring and protecting sensitive data. A DLP policy's PRIMARY function is to define the rules and criteria that the DLP solution uses to identify, monitor, and protect sensitive data (e.g., PII, financial records, intellectual property). The policy tells the system what data is sensitive and what actions to take when

Submitted by weili_xi· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the PRIMARY function of a data loss prevention (DLP) policy when implemented in an organization’s DLP solution?

Options

  • ATo encrypt sensitive data at rest and in transit
  • BTo define rules for monitoring and protecting sensitive data
  • CTo define rules and baselines for network performance
  • DTo detect and block incoming network traffic

How the community answered

(44 responses)
  • A
    9% (4)
  • B
    86% (38)
  • C
    2% (1)
  • D
    2% (1)

Explanation

A DLP policy's PRIMARY function is to define the rules and criteria that the DLP solution uses to identify, monitor, and protect sensitive data (e.g., PII, financial records, intellectual property). The policy tells the system what data is sensitive and what actions to take when a violation is detected. Encryption (A) is a separate security control, network performance baselines (C) describe network management policies, and blocking incoming traffic (D) describes a firewall function - none of these are the core purpose of a DLP policy.

Topics

#DLP (Data Loss Prevention)#Data Protection#Information Security Policies#Security Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice