nerdexam
CompTIA

SY0-501 · Question #44

The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example report file with…

The correct answer is C. Implement a DLP solution on the email gateway to scan email and remove sensitive data or. A coworker inadvertently emailed sensitive customer data, including credit card numbers and PINs, to a non-company account. Implementing a Data Loss Prevention (DLP) solution is the best technical control to prevent such unauthorized disclosures.

Submitted by alyssa_d· Mar 4, 2026Security operations

Question

The security administrator receives an email on a non-company account from a coworker stating that some reports are not exporting correctly. Attached to the email was an example report file with several customers' names and credit card numbers with the PIN. Which of the following is the BEST technical controls that will help mitigate this risk of disclosing sensitive data?

Options

  • AConfigure the mail server to require TLS connections for every email to ensure all transport
  • BCreate a user training program to identify the correct use of email and perform regular audits
  • CImplement a DLP solution on the email gateway to scan email and remove sensitive data or
  • DClassify all data according to its sensitivity and inform the users of data that is prohibited to

How the community answered

(13 responses)
  • A
    15% (2)
  • C
    77% (10)
  • D
    8% (1)

Why each option

A coworker inadvertently emailed sensitive customer data, including credit card numbers and PINs, to a non-company account. Implementing a Data Loss Prevention (DLP) solution is the best technical control to prevent such unauthorized disclosures.

AConfigure the mail server to require TLS connections for every email to ensure all transport

Configuring TLS connections encrypts the email in transit but does not prevent sensitive data from being attached to an email and sent from the originating mail server in the first place.

BCreate a user training program to identify the correct use of email and perform regular audits

Creating a user training program is an administrative control, not a technical control, and relies on human compliance rather than automated enforcement to prevent data disclosure.

CImplement a DLP solution on the email gateway to scan email and remove sensitive data orCorrect

Implementing a Data Loss Prevention (DLP) solution on the email gateway provides the most effective technical control. DLP systems are specifically designed to scan outgoing emails and their attachments for predefined patterns of sensitive data, such as credit card numbers, PII, or PINs. Upon detection, the DLP solution can automatically block the email, remove the sensitive content, or quarantine it, thereby preventing the disclosure of confidential information before it leaves the organizational boundary.

DClassify all data according to its sensitivity and inform the users of data that is prohibited to

Classifying data and informing users are administrative controls that educate users but do not provide an automated technical mechanism to actively stop sensitive data from being sent out.

Concept tested: Data Loss Prevention (DLP) on email gateways

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide

Topics

#DLP#data loss prevention#email security#sensitive data protection

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice