hardMultiple Select
CISA Practice Question: Which TWO of the following are primary objectives…
Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?
⚠ Common exam trap
Many candidates confuse DLP's primary objectives (identify, monitor, control) with supporting or adjacent activities like encryption or compliance, leading them to select options A or E instead of the core DLP functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify and classify sensitive data
Option B is correct because a core objective of any DLP strategy is to discover, identify, and classify sensitive data (e.g., PII, PHI, PCI, intellectual property) so that policies can be applied based on data sensitivity and regulatory category. Option D is correct because DLP's defining function is to monitor and control data movement across endpoints, networks, and cloud channels — inspecting content in use, in motion, and at rest and enforcing actions such as block, quarantine, encrypt, or alert when policy violations occur. Option A is not a primary DLP objective; encryption in transit is typically handled by TLS/IPsec and is a separate control, though DLP may trigger encryption as an enforcement action. Option C is incorrect because DLP augments, rather than replaces, existing security controls like firewalls, IAM, and endpoint protection. Option E is too broad — DLP supports compliance with specific data-handling regulations but does not by itself ensure compliance with all regulations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt all data in transit
Why it's wrong here
Encrypting data in transit protects confidentiality against interception, but DLP objectives centre on discovering, monitoring and blocking sensitive data movement across endpoints, networks and cloud. Transport encryption is a cryptographic control, applicable when data must traverse untrusted networks.
- ✓
Identify and classify sensitive data
Why this is correct
A DLP strategy must first discover where sensitive data resides and label it by classification, since policy enforcement, blocking and reporting all depend on knowing which content is regulated or confidential before any protective control can be applied.
- ✗
Replace all existing security controls
Why it's wrong here
DLP augments existing controls by inspecting and blocking sensitive data flows; it does not supersede endpoint, network or access controls. Replacement suits technology refresh decisions where a legacy control is decommissioned, not the layered monitoring a DLP strategy adds.
- ✓
Monitor and control data movement across endpoints
Why this is correct
DLP enforces policy at the movement layer, watching endpoints, email, cloud uploads and removable media, then blocking, quarantining or alerting when classified data crosses an approved boundary. This satisfies the objective of controlling data movement.
- ✗
Ensure compliance with all regulations
Why it's wrong here
Regulatory compliance is an outcome DLP can support, not a primary objective; DLP exists to identify and prevent unauthorised disclosure of sensitive data. Framing compliance as the objective suits governance and audit programmes, where mapping controls to specific regulatory clauses is the actual task.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.