Courseiva
mediumMultiple ChoiceObjective-mapped

CISA Practice Question: Is implementing a data loss prevention (DLP)…

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to minimize false positives while ensuring sensitive data is protected?

⚠ Common exam trap

Many exam-takers choose exact file matching (Option B) thinking it is the most precise, but they overlook its inability to handle data variations and its reliance on a static database, which leads to both false positives and false negatives in dynamic environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use contextual analysis including user roles and data classification.

Contextual analysis (Option C) is the best approach because it reduces false positives by considering user roles, data classification, and behavioral patterns, ensuring that only genuinely risky data transfers are flagged. Unlike static methods, this dynamic analysis adapts to the organization's data governance policies, allowing legitimate business communications to proceed while still protecting sensitive information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Encrypt all outbound emails containing any attachment.

    Why it's wrong here

    Encrypting all attachments is overly broad and impacts business.

  • Deploy exact file matching against a database of known sensitive documents.

    Why it's wrong here

    Exact matching misses modified or new sensitive files.

  • Use contextual analysis including user roles and data classification.

    Why this is correct

    Contextual analysis reduces false positives by considering behavior and data sensitivity.

  • Apply keyword matching to all outbound emails.

    Why it's wrong here

    Keyword matching produces high false positives.

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.