CAS-004 Security Architecture Practice Question
A security architect is designing a data loss prevention (DLP) program for a global enterprise that uses Microsoft 365, endpoint devices, and a custom web application. The requirement is to detect and block sensitive data exfiltration across all three channels while minimizing false positives caused by legitimate business data that resembles regulated data. The architect needs a control that classifies data consistently and applies policy at the point of egress. Which of the following BEST meets this requirement?
⚠ Common exam trap
The trap here is assuming that network DLP with regex patterns is sufficient for cross-channel protection, when it lacks persistent classification and generates false positives that only exact data match and trainable classifiers can mitigate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply sensitivity labels with unified DLP policies that use exact data match and trainable classifiers across Microsoft 365, endpoints, and the custom application.
Sensitivity labels with unified DLP policies classify data persistently and apply consistent enforcement across Microsoft 365, endpoints, and integrated applications. Exact data match and trainable classifiers improve accuracy by matching real regulated records and learning business context, which reduces false positives while blocking exfiltration at egress points across all channels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require full-disk encryption on all endpoints and enforce TLS for all data in transit to external destinations.
Why it's wrong here
Full-disk encryption and TLS protect data at rest and in transit but do not classify content or prevent authorized users from exfiltrating sensitive data through email, uploads, or the web application. These controls do not inspect data content, so they cannot detect or block exfiltration or reduce false positives.
- ✗
Implement database activity monitoring on all repositories and alert on bulk read operations of sensitive tables.
Why it's wrong here
Database activity monitoring detects suspicious reads from databases but does not cover data already exported to endpoints, Microsoft 365, or the custom web application. It cannot block egress at those channels and provides no persistent classification, so it does not meet the cross-channel requirement.
- ✓
Apply sensitivity labels with unified DLP policies that use exact data match and trainable classifiers across Microsoft 365, endpoints, and the custom application.
Why this is correct
Sensitivity labels persist with the data and provide consistent classification across Microsoft 365, endpoints, and integrated applications. Unified DLP policies using exact data match and trainable classifiers reduce false positives by matching actual regulated records and learning business context, and they enforce policy at egress points across all three channels.
- ✗
Deploy network DLP appliances at each internet egress point and configure regex patterns for regulated data types.
Why it's wrong here
Network DLP can inspect egress traffic, but regex-only patterns generate high false positives and cannot classify data consistently across Microsoft 365, endpoints, and the custom application. It also cannot inspect encrypted traffic without interception, and it lacks context about data origin, so it fails to minimize false positives across all channels.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.