SY0-501 · Question #44
The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example report file with…
The correct answer is C. Implement a DLP solution on the email gateway to scan email and remove sensitive data or. A coworker inadvertently emailed sensitive customer data, including credit card numbers and PINs, to a non-company account. Implementing a Data Loss Prevention (DLP) solution is the best technical control to prevent such unauthorized disclosures.
Question
The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example report file with several customers' names and credit card numbers with the PIN. Which of the following is the BEST technical controls that will help mitigate this risk of disclosing sensitive data?
Options
- AConfigure the mail server to require TLS connections for every email to ensure all transport
- BCreate a user training program to identify the correct use of email and perform regular audits
- CImplement a DLP solution on the email gateway to scan email and remove sensitive data or
- DClassify all data according to its sensitivity and inform the users of data that is prohibited to
How the community answered
(13 responses)- A15% (2)
- C77% (10)
- D8% (1)
Why each option
A coworker inadvertently emailed sensitive customer data, including credit card numbers and PINs, to a non-company account. Implementing a Data Loss Prevention (DLP) solution is the best technical control to prevent such unauthorized disclosures.
Configuring TLS connections encrypts the email in transit but does not prevent sensitive data from being attached to an email and sent from the originating mail server in the first place.
Creating a user training program is an administrative control, not a technical control, and relies on human compliance rather than automated enforcement to prevent data disclosure.
Implementing a Data Loss Prevention (DLP) solution on the email gateway provides the most effective technical control. DLP systems are specifically designed to scan outgoing emails and their attachments for predefined patterns of sensitive data, such as credit card numbers, PII, or PINs. Upon detection, the DLP solution can automatically block the email, remove the sensitive content, or quarantine it, thereby preventing the disclosure of confidential information before it leaves the organizational boundary.
Classifying data and informing users are administrative controls that educate users but do not provide an automated technical mechanism to actively stop sensitive data from being sent out.
Concept tested: Data Loss Prevention (DLP) on email gateways
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.