SY0-301 · Question #205
Which of the following controls would prevent an employee from emailing unencrypted information to their personal email account over the corporate network?
The correct answer is A. DLP. Data Loss Prevention (DLP) inspects outbound network traffic and can block or alert on unencrypted sensitive data sent to unauthorized destinations such as personal email.
Question
Which of the following controls would prevent an employee from emailing unencrypted information to their personal email account over the corporate network?
Options
- ADLP
- BCRL
- CTPM
- DHSM
How the community answered
(51 responses)- A92% (47)
- B2% (1)
- C4% (2)
- D2% (1)
Why each option
Data Loss Prevention (DLP) inspects outbound network traffic and can block or alert on unencrypted sensitive data sent to unauthorized destinations such as personal email.
DLP solutions monitor, detect, and block data in motion across the network based on content policies. A DLP rule can identify unencrypted sensitive content in outbound SMTP traffic destined for external or personal email addresses and prevent the transmission, which directly addresses the described scenario.
A Certificate Revocation List (CRL) tracks revoked digital certificates and has no capability to inspect or block email content.
A Trusted Platform Module (TPM) is a hardware chip used for local key storage and platform integrity checks, not network traffic inspection.
A Hardware Security Module (HSM) manages cryptographic keys and performs encryption operations but does not monitor or block outbound email traffic.
Concept tested: DLP enforcement of data-in-motion email policies
Source: https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
Topics
Community Discussion
No community discussion yet for this question.