nerdexam
Isaca

CISA · Question #618

Which of the following is the PRIMARY objective of data loss prevention (DLP) mechanisms?

The correct answer is C. Protecting against unauthorized transmissions or disclosure of sensitive data. The central goal of DLP is to prevent sensitive data-such as PII, PHI, or intellectual property-from leaving the organization through unauthorized channels. DLP solutions monitor, detect, and block potential data exfiltration via email, endpoints, cloud applications, or removable

Submitted by kev92· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the PRIMARY objective of data loss prevention (DLP) mechanisms?

Options

  • AEnhancing system performance while safeguarding against data loss
  • BAutomating data loss recovery procedures to minimize downtime in case of incidents
  • CProtecting against unauthorized transmissions or disclosure of sensitive data
  • DEnsuring compliance with regulatory requirements for data protection

How the community answered

(64 responses)
  • A
    3% (2)
  • B
    2% (1)
  • C
    94% (60)
  • D
    2% (1)

Explanation

The central goal of DLP is to prevent sensitive data-such as PII, PHI, or intellectual property-from leaving the organization through unauthorized channels. DLP solutions monitor, detect, and block potential data exfiltration via email, endpoints, cloud applications, or removable media. While compliance (D) is often a driver, it is a secondary outcome of implementing DLP. Enhancing performance (A) and recovery automation (B) are not objectives of DLP. ISACA positions DLP as a critical control for confidentiality under DSS05 (Managed Security Services).

Topics

#Data Loss Prevention#Information Security Controls#Data Protection#Sensitive Data Handling

Community Discussion

No community discussion yet for this question.

Full CISA Practice