easyMultiple SelectObjective-mapped
CISA Practice Question: Is implementing a data loss prevention (DLP)…
An organization is implementing a data loss prevention (DLP) solution. Which TWO of the following are key considerations for effective DLP deployment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing DLP in monitoring mode initially to baseline traffic
Options A and D are correct. A: Implementing DLP in monitoring mode initially allows baselining of normal traffic, reducing false positives when policies are enforced later. D: Classifying data based on sensitivity and criticality is fundamental for defining appropriate DLP policies and rules. B is incorrect because policies should be defined before deploying agents to ensure targeted coverage. C is incorrect because encryption is a separate control; DLP can monitor and protect data without requiring encryption of all data. E is incorrect because DLP does not replace user security awareness training; it is a technical control that complements training.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing DLP in monitoring mode initially to baseline traffic
Why this is correct
Monitoring first helps tune policies and reduce false positives.
- ✗
Deploying DLP agents on all endpoints before defining policies
Why it's wrong here
Policies should be defined before deployment to avoid disruption.
- ✗
Encrypting all data at rest and in transit as a prerequisite
Why it's wrong here
Encryption is a separate control; DLP can work with or without it.
- ✓
Classifying data based on sensitivity and criticality
Why this is correct
Data classification is essential to define DLP policies.
- ✗
Replacing user security awareness training with automated DLP
Why it's wrong here
DLP complements but does not replace training.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is implementing a data loss prevention (DLP) solution. Which of the following is the MOST important step to ensure the DLP rules are effective?
easy- ✓ A.Classify data based on sensitivity
- B.Encrypt all data at rest
- C.Establish an incident response team
- D.Create user awareness training
Why A: Data classification is the foundational step for effective DLP rules because it defines which data is sensitive and how it should be handled. Without classification, DLP policies cannot accurately identify or enforce rules on sensitive content, leading to false positives or missed detections. Classification enables the DLP system to apply context-aware rules (e.g., regex patterns for PII, keywords for confidential documents) that align with the organization's data governance requirements.
Variation 2. Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?
hard- A.Encrypt all data in transit
- ✓ B.Identify and classify sensitive data
- C.Replace all existing security controls
- ✓ D.Monitor and control data movement across endpoints
- E.Ensure compliance with all regulations
Why B: Identifying and classifying sensitive data is the foundational step in a DLP strategy. Without knowing where sensitive data resides (e.g., PII, PCI, IP), DLP policies cannot accurately detect or prevent unauthorized transfers. Classification enables the DLP system to apply context-aware rules, such as blocking credit card numbers in email attachments or flagging confidential documents uploaded to cloud storage.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.