easyMultiple Select
CISA Practice Question: Is implementing a data loss prevention (DLP)…
An organization is implementing a data loss prevention (DLP) solution. Which TWO of the following are key considerations for effective DLP deployment?
⚠ Common exam trap
CISA often tests candidates who assume DLP should be deployed in blocking mode immediately or that encryption alone satisfies DLP, rather than recognizing the need for baselining and data classification first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing DLP in monitoring mode initially to baseline traffic
Option A is correct because deploying DLP in monitoring (discovery/audit) mode first lets the organization baseline normal data flows, identify false positives, and tune policies before enforcing blocking actions, which minimizes business disruption. Option D is correct because effective DLP fundamentally depends on data classification—labeling data by sensitivity and criticality (e.g., PII, PHI, IP) so policies can accurately identify what to protect and how. Option B is wrong because policies and classification must be defined before agent rollout; deploying agents first without policies provides no meaningful protection and creates management overhead. Option C is wrong because encryption at rest and in transit is a complementary data-protection control, not a prerequisite for DLP deployment. Option E is wrong because DLP augments, not replaces, user security awareness training, which remains essential for reducing human-driven data loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing DLP in monitoring mode initially to baseline traffic
Why this is correct
Deploying DLP in monitoring mode first establishes a behavioural baseline of sensitive-data flows without blocking legitimate business activity. This satisfies the stem's requirement for effective deployment by revealing false positives and policy gaps before enforcement, letting the organisation tune rules and classify data accurately prior to switching to active blocking.
- ✗
Deploying DLP agents on all endpoints before defining policies
Why it's wrong here
Agents deployed before policies exist collect and forward data with no rules governing classification, destinations or user actions, so the deployment cannot enforce anything. Defining policies first is the prerequisite. Endpoint agents are genuinely required where data leaves via USB, print or local copy, but only once policy scope is settled.
- ✗
Encrypting all data at rest and in transit as a prerequisite
Why it's wrong here
Encryption protects data confidentiality but does not classify content, monitor egress channels or prevent unauthorised transfer, so it cannot substitute for DLP policy enforcement. It tempts because encryption and DLP are both data-protection controls, yet encryption is a complementary safeguard rather than a prerequisite consideration for DLP deployment.
- ✓
Classifying data based on sensitivity and criticality
Why this is correct
Classification drives every DLP policy decision: without sensitivity labels, rules cannot distinguish regulated personal data from public content, so enforcement either blocks too much or too little. Mapping criticality also prioritises monitoring and protection effort, directly satisfying the stem's requirement for effective deployment across the organisation's data estate.
- ✗
Replacing user security awareness training with automated DLP
Why it's wrong here
DLP cannot replace user security awareness training; automated policies misclassify data and users must understand handling rules and incident reporting. It tempts because DLP reduces reliance on manual vigilance, but training and DLP are complementary controls, and removing training weakens the human layer the deployment depends on.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is implementing a data loss prevention (DLP) solution. Which of the following is the MOST important step to ensure the DLP rules are effective?
easy- ✓ A.Classify data based on sensitivity
- B.Encrypt all data at rest
- C.Establish an incident response team
- D.Create user awareness training
Why A: Data classification is the foundational step for effective DLP rules because it defines which data is sensitive and how it should be handled. Without classification, DLP policies cannot accurately identify or enforce rules on sensitive content, leading to false positives or missed detections. Classification enables the DLP system to apply context-aware rules (e.g., regex patterns for PII, keywords for confidential documents) that align with the organization's data governance requirements.
Variation 2. Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?
hard- A.Encrypt all data in transit
- ✓ B.Identify and classify sensitive data
- C.Replace all existing security controls
- ✓ D.Monitor and control data movement across endpoints
- E.Ensure compliance with all regulations
Why B: Option B is correct because a core objective of any DLP strategy is to discover, identify, and classify sensitive data (e.g., PII, PHI, PCI, intellectual property) so that policies can be applied based on data sensitivity and regulatory category. Option D is correct because DLP's defining function is to monitor and control data movement across endpoints, networks, and cloud channels — inspecting content in use, in motion, and at rest and enforcing actions such as block, quarantine, encrypt, or alert when policy violations occur. Option A is not a primary DLP objective; encryption in transit is typically handled by TLS/IPsec and is a separate control, though DLP may trigger encryption as an enforcement action. Option C is incorrect because DLP augments, rather than replaces, existing security controls like firewalls, IAM, and endpoint protection. Option E is too broad — DLP supports compliance with specific data-handling regulations but does not by itself ensure compliance with all regulations.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.