CAS-004 Security Architecture Practice Question
A security architect is designing a data loss prevention (DLP) program for a company that uses Microsoft 365 and a SaaS CRM. The architect must reduce false positives while still detecting sensitive data leaving the environment. Which TWO capabilities should be prioritized? (Choose two.)
⚠ Common exam trap
The trap here is assuming broader detection rules always improve DLP, when in fact overly broad patterns and keywords drive false positives and analyst fatigue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trainable classifiers that learn from labeled examples of the organization's confidential documents
High-fidelity DLP combines exact data matching, which fingerprints the organization's own sensitive records, with trainable classifiers that recognize document categories from labeled examples. Together they detect both known data and semantically sensitive content while avoiding the noise of generic regex or keyword rules. Size limits and broad patterns do not target sensitive content and increase false positives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Blocking all outbound email attachments larger than 10 MB
Why it's wrong here
A size-based rule has no understanding of data sensitivity and will block legitimate business documents while allowing small files containing regulated data. It neither targets sensitive content nor reduces false positives in a meaningful way, so it is not a suitable DLP detection capability.
- ✗
Keyword lists built from common industry terms such as 'confidential' and 'internal use'
Why it's wrong here
Keyword lists are easily triggered by boilerplate footers and disclaimers, producing many false positives. They also miss sensitive data that lacks the keyword, so they are a weak primary detection method and do not support the goal of high-fidelity detection with fewer false alarms.
- ✓
Trainable classifiers that learn from labeled examples of the organization's confidential documents
Why this is correct
Trainable classifiers use machine learning on labeled samples to recognize categories such as contracts or source code, which pattern matching cannot. Combining them with EDM lets the program detect both known records and semantic categories, improving coverage without flooding analysts with false positives from generic regex rules.
- ✓
Exact data matching (EDM) against a hashed fingerprint of the organization's customer records
Why this is correct
EDM creates a hashed fingerprint of specific sensitive records so the DLP engine matches only the organization's actual data, dramatically reducing false positives compared with generic pattern matching. It is well suited to detecting exfiltration of customer records from email and SaaS uploads while preserving privacy because the raw values are not stored.
- ✗
Regular expressions that match any nine-digit number as a potential account identifier
Why it's wrong here
A broad regex for nine-digit numbers will match phone numbers, order IDs, and many other benign values, generating large volumes of false positives. It does not distinguish the organization's real sensitive data, so it works against the stated goal of reducing false positives while improving detection quality.
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.