220-1102 Security Practice Question
A security audit reveals that sensitive customer data was emailed to a third-party vendor without encryption. The company policy mandates that all sensitive data must be encrypted at rest and in transit. Which security control should be implemented to prevent such incidents in the future?
⚠ Common exam trap
Candidates often confuse encryption at rest (FDE) with encryption in transit, or they assume that email filtering alone can prevent data leaks, failing to recognize that DLP is the specific control designed to inspect and enforce policies on data in motion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP) software
Data Loss Prevention (DLP) software is designed to monitor, detect, and block unauthorized transmission of sensitive data, such as customer information, via email or other channels. In this scenario, DLP would enforce the company's encryption policy by scanning outgoing emails for sensitive content and either blocking the unencrypted message or automatically applying encryption before sending. This directly addresses the root cause—data leaving the organization without encryption in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Loss Prevention (DLP) software
Why this is correct
Data Loss Prevention (DLP) software is the correct choice because it performs deep content inspection on outbound email, using pattern matching, exact data matching, and fingerprinting to identify sensitive data such as credit card numbers or personally identifiable information (PII). When such data is detected, DLP can automatically block the message, quarantine it, or apply encryption in real time, enforcing the company's data protection policy and providing a forensic audit trail for compliance.
- ✗
Full Disk Encryption (FDE) on workstations
Why it's wrong here
Full Disk Encryption (FDE) on workstations protects only data at rest by encrypting the entire hard drive, including the OS, applications, and files. However, once the user authenticates and the system is running, the encryption layer is transparent, so files are decrypted in memory and sent over email in plaintext; FDE has no visibility into outbound content and cannot inspect or prevent data from being written to a message. While FDE is essential against device theft, it is completely ineffective for this email-based data exfiltration scenario.
- ✗
Email filtering and anti-spam software
Why it's wrong here
Email filtering and anti-spam software operates primarily on message origin, reputation, and signature-based detections, classifying traffic as spam, phishing, or malware-laced based on known patterns and heuristics. These tools do not typically perform policy-driven content analysis to recognize that a message body contains sensitive customer data, nor can they automatically enforce encryption or redaction based on data classification. Their purpose is to keep malicious or unsolicited messages out of the inbox, not to inspect or police the content of legitimate outbound correspondence.
- ✗
Access control lists (ACLs) on file servers
Why it's wrong here
Access control lists (ACLs) on file servers govern what authenticated users can read, write, or delete at the file and directory level, preventing unauthorized users from opening sensitive documents. However, once a user with legitimate read permission opens a customer data file, ACLs have no mechanism to observe that the user's email client now contains a copy of that data in a draft, nor can they intervene when the email is transmitted. ACLs secure the file store itself, but they cannot control what happens after a trusted user retrieves the data and sends it through an unrelated channel.
Go deeper
Related to this question
Learn chapter
Wireless Encryption: WEP, WPA, WPA2, WPA3
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.