Courseiva
easyMultiple Choice

CISA Practice Question: Wants to protect its intellectual property from…

An organization wants to protect its intellectual property from unauthorized disclosure via email. Which control should be implemented?

⚠ Common exam trap

Watch out — candidates often confuse encryption (which protects data in transit) with data loss prevention (which controls what data can leave the organization), leading candidates to choose encryption as a catch-all security measure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a data loss prevention (DLP) system.

A DLP system is the correct control because it can inspect email content and attachments in real time, applying policies to block or quarantine unauthorized disclosures of intellectual property. Unlike encryption, which only protects data in transit but does not prevent an authorized user from sending sensitive information, DLP provides content-aware enforcement at the point of transmission.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypt all outgoing emails.

    Why it's wrong here

    Encrypting all outgoing email protects content in transit but does not prevent an authorised insider from sending intellectual property to an external recipient, since the sender holds the keys. It is tempting because encryption addresses interception, and would be correct where the threat is message disclosure en route rather than exfiltration by legitimate users.

  • ✓

    Implement a data loss prevention (DLP) system.

    Why this is correct

    A data loss prevention system inspects email content and attachments, then blocks or quarantines messages matching sensitive-data policies, such as intellectual property fingerprints. This directly enforces the confidentiality objective by preventing unauthorised disclosure at the point of egress, satisfying the requirement to stop proprietary information leaving the organisation via email.

  • ✗

    Disable email altogether.

    Why it's wrong here

    Disabling email entirely removes the exfiltration channel but also removes a business-critical communication service, so it cannot be implemented as a control. It is tempting as an absolute denial measure, and would be correct only in an isolated environment where no legitimate external email traffic is required at all.

  • ✗

    Require employees to sign non-disclosure agreements.

    Why it's wrong here

    Non-disclosure agreements create legal liability after disclosure but apply no technical or procedural restriction on email, so they cannot prevent the transfer itself. They are tempting because they are contractual and inexpensive, and would be correct as a supporting deterrent alongside data loss prevention, not as the primary control.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.