CISA · Question #460
When reviewing the monitoring and prevention of sensitive data moving out of an organization's network, which of the following is MOST important for an IS auditor to verify?
The correct answer is C. Deep packet inspection is enabled. Deep packet inspection provides the ability to examine packet payloads for sensitive content (not just headers), enabling detection and blocking of confidential data in motion. Without DPI, encrypted or non-standard traffic could bypass perimeter controls, undermining any monitor
Question
When reviewing the monitoring and prevention of sensitive data moving out of an organization’s network, which of the following is MOST important for an IS auditor to verify?
Options
- ATransport Layer Security (TLS) is used
- BFirewall rules have been documented
- CDeep packet inspection is enabled
- DChain of custody is followed
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C86% (24)
- D7% (2)
Explanation
Deep packet inspection provides the ability to examine packet payloads for sensitive content (not just headers), enabling detection and blocking of confidential data in motion. Without DPI, encrypted or non-standard traffic could bypass perimeter controls, undermining any monitoring or prevention efforts.
Topics
Community Discussion
No community discussion yet for this question.