Courseiva

200-201 Security Policies and Procedures Practice Question

A security analyst is tasked with developing a data loss prevention (DLP) strategy for the organization. The strategy must align with the CyberOps Associate curriculum and address both endpoint and network-based data exfiltration. Which two actions should the analyst include in the strategy? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse data-at-rest protection like encryption with data-in-motion controls, which are the core of DLP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy network DLP solutions to inspect outbound traffic for sensitive data patterns and block unauthorized transfers.

The two actions to include are endpoint DLP and network DLP. Endpoint DLP controls data transfers at the device level, such as to USB drives or cloud services, while network DLP inspects outbound traffic for sensitive data. Together, they provide comprehensive coverage for data exfiltration across both endpoints and the network. These technical controls directly address the requirement to monitor and prevent unauthorized data transfers, aligning with the CyberOps Associate curriculum's focus on data protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy network DLP solutions to inspect outbound traffic for sensitive data patterns and block unauthorized transfers.

    Why this is correct

    Network DLP monitors data in transit across the network perimeter. It can detect and block sensitive information leaving the organization via email, web uploads, or other protocols. This complements endpoint DLP by providing a centralized enforcement point and covering devices that may not have agents installed. Together, they form a layered defense against data exfiltration, as recommended by security best practices.

  • ✗

    Implement role-based access control (RBAC) to limit access to sensitive data.

    Why it's wrong here

    RBAC restricts who can access data, reducing the risk of insider threats, but it does not monitor or prevent the transfer of data once accessed. DLP is concerned with detecting and blocking unauthorized exfiltration, not just access control. RBAC is a complementary measure but not a core DLP action for monitoring data movement.

  • ✓

    Implement endpoint DLP agents to monitor and control data transfers to removable media and cloud storage.

    Why this is correct

    Endpoint DLP agents provide visibility and control over data movement at the source. They can block or log attempts to copy sensitive data to USB drives, upload to personal cloud storage, or send via email. This is essential for preventing exfiltration from individual devices, especially in remote work scenarios. The CyberOps Associate curriculum emphasizes endpoint security as a critical component of data protection.

  • ✗

    Configure full-disk encryption on all endpoints to prevent data loss if a device is stolen.

    Why it's wrong here

    Full-disk encryption protects data at rest on a lost or stolen device, but it does not prevent an authorized user from intentionally or unintentionally exfiltrating data. DLP focuses on data in use and in motion, not just at rest. While encryption is important, it does not address the scenario's requirement to monitor and control data transfers, so it is not a direct component of a DLP strategy.

  • ✗

    Establish a security awareness program to educate employees about data handling policies.

    Why it's wrong here

    Security awareness is valuable for reducing accidental data leaks, but it is not a technical control that enforces DLP. It supports the overall strategy but does not directly monitor or block data exfiltration. The scenario asks for actions to include in a DLP strategy, which typically involve technical solutions for detection and prevention, not just training.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.