mediumMultiple ChoiceObjective-mapped
CISA Practice Question: Is implementing a data loss prevention (DLP)…
An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to minimize false positives while ensuring sensitive data is protected?
⚠ Common exam trap
Many exam-takers choose exact file matching (Option B) thinking it is the most precise, but they overlook its inability to handle data variations and its reliance on a static database, which leads to both false positives and false negatives in dynamic environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use contextual analysis including user roles and data classification.
Contextual analysis (Option C) is the best approach because it reduces false positives by considering user roles, data classification, and behavioral patterns, ensuring that only genuinely risky data transfers are flagged. Unlike static methods, this dynamic analysis adapts to the organization's data governance policies, allowing legitimate business communications to proceed while still protecting sensitive information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt all outbound emails containing any attachment.
Why it's wrong here
Encrypting all attachments is overly broad and impacts business.
- ✗
Deploy exact file matching against a database of known sensitive documents.
Why it's wrong here
Exact matching misses modified or new sensitive files.
- ✓
Use contextual analysis including user roles and data classification.
Why this is correct
Contextual analysis reduces false positives by considering behavior and data sensitivity.
- ✗
Apply keyword matching to all outbound emails.
Why it's wrong here
Keyword matching produces high false positives.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.