Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is designing a data loss prevention (DLP) program for a multinational retailer that processes payment card data and personally identifiable information. The program must discover sensitive data at rest across on-premises file shares and cloud storage, and it must prevent sensitive data from leaving the organization through email and web uploads. Which two capabilities are essential for this program? (Choose two.)

⚠ Common exam trap

The trap here is selecting adjacent data-protection controls such as encryption or segmentation that secure data but do not inspect content or enforce egress policy, which are the actual DLP functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Content inspection using pattern matching and data classifiers to identify regulated data types.

A functioning DLP program needs both accurate identification of regulated content and an enforcement point where policy can act. Content inspection with classifiers supplies the identification, while egress enforcement at email and web gateways supplies the prevention. Encryption, SIEM correlation, and segmentation are valuable controls but do not deliver either of the two required DLP capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security information and event management (SIEM) correlation of DLP alerts with threat intelligence feeds.

    Why it's wrong here

    SIEM correlation improves detection and investigation of security incidents, but it is a monitoring and analytics function. It does not inspect content to identify regulated data, nor does it block email or web uploads, so it cannot fulfill either the discovery or the prevention requirement on its own.

  • ✓

    Content inspection using pattern matching and data classifiers to identify regulated data types.

    Why this is correct

    Content inspection with pattern matching and classifiers is the foundation of any DLP program because it identifies regulated data such as card numbers and PII within files, messages, and uploads. Without accurate classification, neither discovery at rest nor prevention in motion can distinguish sensitive content from ordinary business data, so this capability is essential to meet both stated requirements.

  • ✓

    Enforcement policies applied at egress points such as email gateways and secure web gateways.

    Why this is correct

    Enforcement at egress points is what turns classification into prevention. Email gateways and secure web gateways intercept outbound messages and uploads, apply the DLP policy, and can block, quarantine, or encrypt sensitive content. Without an enforcement channel, discovery alone would not satisfy the requirement to stop regulated data from leaving the organization.

  • ✗

    Full-disk encryption on all endpoint devices and servers that store regulated data.

    Why it's wrong here

    Full-disk encryption protects data if a device is physically lost or stolen, but it does not identify sensitive content, discover it on file shares and cloud storage, or prevent it from being emailed or uploaded. It addresses a different threat model and provides no inspection or enforcement capability for the DLP requirements described.

  • ✗

    Network segmentation of the cardholder data environment using internal firewalls.

    Why it's wrong here

    Segmentation limits the scope of systems subject to payment card requirements and reduces lateral movement, but it does not examine data content, discover regulated data at rest, or stop sensitive information from being transmitted through email and web channels. It is a scoping and containment control, not a DLP capability.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.