nerdexam
Isaca

CISA · Question #460

When reviewing the monitoring and prevention of sensitive data moving out of an organization's network, which of the following is MOST important for an IS auditor to verify?

The correct answer is C. Deep packet inspection is enabled. Deep packet inspection provides the ability to examine packet payloads for sensitive content (not just headers), enabling detection and blocking of confidential data in motion. Without DPI, encrypted or non-standard traffic could bypass perimeter controls, undermining any monitor

Submitted by olafpl· Apr 18, 2026Protection of Information Assets

Question

When reviewing the monitoring and prevention of sensitive data moving out of an organization’s network, which of the following is MOST important for an IS auditor to verify?

Options

  • ATransport Layer Security (TLS) is used
  • BFirewall rules have been documented
  • CDeep packet inspection is enabled
  • DChain of custody is followed

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    86% (24)
  • D
    7% (2)

Explanation

Deep packet inspection provides the ability to examine packet payloads for sensitive content (not just headers), enabling detection and blocking of confidential data in motion. Without DPI, encrypted or non-standard traffic could bypass perimeter controls, undermining any monitoring or prevention efforts.

Topics

#Data Loss Prevention (DLP)#Deep Packet Inspection (DPI)#Data Exfiltration#Network Security

Community Discussion

No community discussion yet for this question.

Full CISA Practice