A security architect is designing a data loss prevention (DLP) program for a multinational retailer that processes payment card data and personally identifiable information. The program must discover sensitive data at rest across on-premises file shares and cloud storage, and it must prevent sensitive data from leaving the organization through email and web uploads. Which two capabilities are essential for this program? (Choose two.)
Content inspection with pattern matching and classifiers is the foundation of any DLP program because it identifies regulated data such as card numbers and PII within files, messages, and uploads. Without accurate classification, neither discovery at rest nor prevention in motion can distinguish sensitive content from ordinary business data, so this capability is essential to meet both stated requirements.
Why this answer
A functioning DLP program needs both accurate identification of regulated content and an enforcement point where policy can act. Content inspection with classifiers supplies the identification, while egress enforcement at email and web gateways supplies the prevention. Encryption, SIEM correlation, and segmentation are valuable controls but do not deliver either of the two required DLP capabilities.
Exam trap
The trap here is selecting adjacent data-protection controls such as encryption or segmentation that secure data but do not inspect content or enforce egress policy, which are the actual DLP functions.