nerdexam
CompTIA

SY0-301 · Question #680

Several departments within a company have a business need to send high volumes of confidential information to customers via email. Which of the following is the BEST solution to mitigate…

The correct answer is A. Employ encryption on all outbound emails containing confidential information. Encrypting all outbound emails containing confidential information is the most direct and effective technical control to prevent unauthorized disclosure of that data to unintended recipients.

Security operations

Question

Several departments within a company have a business need to send high volumes of confidential information to customers via email. Which of the following is the BEST solution to mitigate unintentional exposure of confidential information?

Options

  • AEmploy encryption on all outbound emails containing confidential information.
  • BEmploy exact data matching and prevent inbound emails with Data Loss Prevention.
  • CEmploy hashing on all outbound emails containing confidential information.
  • DEmploy exact data matching and encrypt inbound e-mails with Data Loss Prevention.

How the community answered

(50 responses)
  • A
    76% (38)
  • B
    4% (2)
  • C
    8% (4)
  • D
    12% (6)

Why each option

Encrypting all outbound emails containing confidential information is the most direct and effective technical control to prevent unauthorized disclosure of that data to unintended recipients.

AEmploy encryption on all outbound emails containing confidential information.Correct

Applying encryption to outbound emails ensures that even if a confidential message is intercepted or delivered to the wrong recipient, the content remains unreadable without the decryption key. This directly addresses the risk of unintentional exposure by protecting the data in transit and at rest in the recipient's mailbox.

BEmploy exact data matching and prevent inbound emails with Data Loss Prevention.

Exact data matching with DLP applied to inbound emails protects against data entering the organization, not confidential data leaving it; the question is about outbound confidential information.

CEmploy hashing on all outbound emails containing confidential information.

Hashing produces a one-way digest used for integrity verification and cannot be reversed to recover the original data, making it unsuitable for protecting confidential content that recipients need to read.

DEmploy exact data matching and encrypt inbound e-mails with Data Loss Prevention.

Encrypting inbound emails with DLP addresses data coming into the organization, which is the opposite of the outbound confidentiality requirement described.

Concept tested: Email encryption for outbound data loss prevention

Source: https://learn.microsoft.com/en-us/purview/email-encryption

Topics

#DLP#email encryption#data loss prevention#confidential data

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice