hardMultiple Choice
CISA Practice Question: A multinational corporation is deploying a data…
A multinational corporation is deploying a data loss prevention (DLP) solution across its network. The DLP system must be configured to prevent the exfiltration of personally identifiable information (PII) while minimizing false positives. Which approach is most effective?
⚠ Common exam trap
CISA often tests the misconception that encryption or training alone satisfies DLP requirements, or that simple keyword blocking is sufficient; the exam expects context-aware, layered detection to balance security and false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use regex patterns for PII combined with context-aware policies (e.g., user role, destination domain)
The most effective DLP approach combines regex-based detection of PII patterns with context-aware policies that consider user role, destination domain, and other metadata. This reduces false positives by only blocking or alerting when sensitive data is leaving in a risky context (e.g., a finance user sending to an external domain), while allowing legitimate business flows. Pure pattern matching without context generates excessive false positives, and encryption or training alone do not prevent exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block all outbound email containing keywords such as 'SSN' or 'credit card'
Why it's wrong here
Keyword blocking matches literal strings, so it misses PII in attachments, images or formatted numbers while flagging innocuous mentions, producing the false positives the scenario forbids. It is tempting as a quick content filter, and would suit environments needing crude blocking of obvious terms rather than accurate PII detection.
- ✗
Require all users to complete annual data handling training and rely on self-reporting
Why it's wrong here
Training and self-reporting rely on human behaviour and cannot enforce prevention or inspect traffic, so exfiltration continues undetected and false positives are irrelevant. It is tempting because awareness programmes reduce risk culturally, and would be correct where the objective is building a compliance culture rather than technically preventing data movement.
- ✗
Implement full disk encryption on all endpoints and encrypt all outbound traffic
Why it's wrong here
Encryption protects data at rest and in transit but cannot inspect content, so PII still leaves via email or uploads; it addresses confidentiality of intercepted data, not exfiltration prevention. It is tempting because encryption is a core data-protection control, and would be correct when the requirement is protecting stored or transmitted data from unauthorised disclosure.
- ✓
Use regex patterns for PII combined with context-aware policies (e.g., user role, destination domain)
Why this is correct
Regex alone matches any 16-digit string, generating false positives on order numbers and test data. Layering context-aware policies — user role and destination domain — narrows matches to genuine exfiltration attempts, satisfying the stem's dual requirement to block PII while minimising false positives.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.