mediumMultiple Choice
CISA Practice Question: Is implementing a data loss prevention (DLP)…
An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to minimize false positives while ensuring sensitive data is protected?
⚠ Common exam trap
Many exam-takers choose exact file matching (Option B) thinking it is the most precise, but they overlook its inability to handle data variations and its reliance on a static database, which leads to both false positives and false negatives in dynamic environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use contextual analysis including user roles and data classification.
Contextual analysis (Option C) is the best approach because it reduces false positives by considering user roles, data classification, and behavioral patterns, ensuring that only genuinely risky data transfers are flagged. Unlike static methods, this dynamic analysis adapts to the organization's data governance policies, allowing legitimate business communications to proceed while still protecting sensitive information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt all outbound emails containing any attachment.
Why it's wrong here
Blanket encryption of any attachment ignores content, so it neither identifies sensitive data nor reduces false positives; it simply obscures everything. Encryption is the right control for protecting data in transit, but DLP classification requires content inspection against defined sensitive-data patterns.
- ✗
Deploy exact file matching against a database of known sensitive documents.
Why it's wrong here
Exact file matching only flags documents already fingerprinted in the database, so any reformatted, renamed or newly created sensitive file passes undetected. It is tempting because hashes give near-zero false positives, but it is the correct choice only when protecting a fixed, known set of files.
- ✓
Use contextual analysis including user roles and data classification.
Why this is correct
Contextual analysis correlates user roles, data classification and destination, so DLP policies trigger only on genuinely risky transfers rather than every pattern match. This precision reduces false positives while preserving protection of sensitive data, satisfying both stem requirements simultaneously.
- ✗
Apply keyword matching to all outbound emails.
Why it's wrong here
Keyword matching flags any message containing a chosen word, generating heavy false positives from ordinary business language. It is tempting for its simplicity and broad coverage, but it is appropriate only for coarse monitoring, not for a DLP deployment whose stated goal is minimising false positives.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.