CISA · Question #652
Which of the following would be of MOST concern to an IS auditor reviewing a data loss prevention (DLP) solution implementation for endpoints?
The correct answer is D. The solution has been implemented in blocking mode prior to performing tuning.. DLP solutions typically go through a monitoring (learning) phase before being switched to blocking mode. This tuning phase is critical for identifying false positives - legitimate business activities that the DLP rules would incorrectly block. Implementing a DLP solution in block
Question
Which of the following would be of MOST concern to an IS auditor reviewing a data loss prevention (DLP) solution implementation for endpoints?
Options
- AThe solution does not prevent data leakage because it is still in the monitoring phase.
- BThe organization has never finished tuning the solution.
- CThe DLP solution does not support all types of servers.
- DThe solution has been implemented in blocking mode prior to performing tuning.
How the community answered
(43 responses)- A12% (5)
- B19% (8)
- C5% (2)
- D65% (28)
Explanation
DLP solutions typically go through a monitoring (learning) phase before being switched to blocking mode. This tuning phase is critical for identifying false positives - legitimate business activities that the DLP rules would incorrectly block. Implementing a DLP solution in blocking mode before performing tuning (D) is the MOST concerning because it means legitimate business operations may be blocked without warning, causing operational disruption, and conversely, the rules may not yet be calibrated to catch actual data leakage accurately. Option A (still in monitoring phase) is normal and expected during initial deployment - monitoring mode is part of the proper implementation process, not a concern. Option B (never finishing tuning) is a concern but less severe than prematurely activating blocking mode. Option C (not supporting all server types) is a coverage gap but not as immediately harmful. Blocking mode before tuning inverts the proper implementation sequence and risks both operational disruption and false security confidence.
Topics
Community Discussion
No community discussion yet for this question.