nerdexam
(ISC)2

CSSLP · Question #93

Which of the following actions does the Data Loss Prevention (DLP) technology take when an agent detects a policy violation for data of all states? Each correct answer represents a complete…

The correct answer is A. It creates an alert. B. It quarantines the file to a secure location. D. It blocks the transmission of content. Data Loss Prevention (DLP) technology responds to policy violations by creating alerts, quarantining non-compliant files, and blocking the transmission of sensitive content.

Secure Software Concepts

Question

Which of the following actions does the Data Loss Prevention (DLP) technology take when an agent detects a policy violation for data of all states? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AIt creates an alert.
  • BIt quarantines the file to a secure location.
  • CIt reconstructs the session.
  • DIt blocks the transmission of content.

How the community answered

(30 responses)
  • A
    93% (28)
  • C
    7% (2)

Why each option

Data Loss Prevention (DLP) technology responds to policy violations by creating alerts, quarantining non-compliant files, and blocking the transmission of sensitive content.

AIt creates an alert.Correct

DLP systems are designed to generate alerts to security administrators or compliance officers whenever a policy violation is detected, notifying them of potential data breaches or misuse.

BIt quarantines the file to a secure location.Correct

When a DLP agent detects sensitive data that violates a policy, it can quarantine the file, moving it to a secure, isolated location to prevent unauthorized access or further propagation.

CIt reconstructs the session.

Reconstructing a session is typically a function of network forensic tools or some IDS/IPS systems for analysis, not a direct protective action taken by DLP against a policy violation.

DIt blocks the transmission of content.Correct

A primary function of DLP is to prevent unauthorized outbound transmission of sensitive data by actively blocking the content from leaving the organization's control, whether through email, cloud uploads, or USB devices.

Concept tested: Data Loss Prevention (DLP) Actions

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide

Topics

#Data Loss Prevention#DLP actions#Data Protection#Security Controls

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice