CISA · Question #618
Which of the following is the PRIMARY objective of data loss prevention (DLP) mechanisms?
The correct answer is C. Protecting against unauthorized transmissions or disclosure of sensitive data. The central goal of DLP is to prevent sensitive data-such as PII, PHI, or intellectual property-from leaving the organization through unauthorized channels. DLP solutions monitor, detect, and block potential data exfiltration via email, endpoints, cloud applications, or removable
Question
Which of the following is the PRIMARY objective of data loss prevention (DLP) mechanisms?
Options
- AEnhancing system performance while safeguarding against data loss
- BAutomating data loss recovery procedures to minimize downtime in case of incidents
- CProtecting against unauthorized transmissions or disclosure of sensitive data
- DEnsuring compliance with regulatory requirements for data protection
How the community answered
(64 responses)- A3% (2)
- B2% (1)
- C94% (60)
- D2% (1)
Explanation
The central goal of DLP is to prevent sensitive data-such as PII, PHI, or intellectual property-from leaving the organization through unauthorized channels. DLP solutions monitor, detect, and block potential data exfiltration via email, endpoints, cloud applications, or removable media. While compliance (D) is often a driver, it is a secondary outcome of implementing DLP. Enhancing performance (A) and recovery automation (B) are not objectives of DLP. ISACA positions DLP as a critical control for confidentiality under DSS05 (Managed Security Services).
Topics
Community Discussion
No community discussion yet for this question.