PSE-SASE · Question #6
Which statement describes the data loss prevention (DLP) add-on?
The correct answer is C. It is a centrally delivered cloud service with unified detection policies that can be embedded in. Option C correctly characterizes a modern DLP add-on as a centrally delivered cloud service with unified detection policies - this is the defining architectural feature of enterprise DLP solutions, where policies are managed from a single cloud console and enforced consistently…
Question
Which statement describes the data loss prevention (DLP) add-on?
Options
- AIt prevents phishing attacks by controlling the sites to which users can submit valid corporate
- BIt employs automated policy enforcement to allow trusted behavior with a new Device-ID policy
- CIt is a centrally delivered cloud service with unified detection policies that can be embedded in
- DIt enables data sharing with third-party tools such as security information and event management
How the community answered
(19 responses)- B5% (1)
- C89% (17)
- D5% (1)
Explanation
Option C correctly characterizes a modern DLP add-on as a centrally delivered cloud service with unified detection policies - this is the defining architectural feature of enterprise DLP solutions, where policies are managed from a single cloud console and enforced consistently across channels (email, web, endpoints, cloud apps).
Why the distractors are wrong:
- A describes anti-phishing or URL-filtering functionality (restricting where users submit credentials), which is a separate security control unrelated to data loss prevention.
- B describes a device trust or Zero Trust Network Access (ZTNA) policy mechanism using Device-ID - a feature tied to network access control, not data classification or exfiltration prevention.
- D describes SIEM/log integration or data-sharing capabilities, which is a complementary feature a security platform might offer, but it is not what defines or describes DLP itself.
Memory tip: Think of DLP as a cloud umbrella - it sits centrally overhead and casts the same detection policies across all your traffic and data flows from one place. If an answer option describes DLP as doing something other than detecting and preventing sensitive data from leaving, it's likely wrong.
Topics
Community Discussion
No community discussion yet for this question.