Courseiva
hardMultiple Select

CISA Practice Question: Which TWO of the following are primary objectives…

Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?

⚠ Common exam trap

Many candidates confuse DLP's primary objectives (identify, monitor, control) with supporting or adjacent activities like encryption or compliance, leading them to select options A or E instead of the core DLP functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify and classify sensitive data

Option B is correct because a core objective of any DLP strategy is to discover, identify, and classify sensitive data (e.g., PII, PHI, PCI, intellectual property) so that policies can be applied based on data sensitivity and regulatory category. Option D is correct because DLP's defining function is to monitor and control data movement across endpoints, networks, and cloud channels — inspecting content in use, in motion, and at rest and enforcing actions such as block, quarantine, encrypt, or alert when policy violations occur. Option A is not a primary DLP objective; encryption in transit is typically handled by TLS/IPsec and is a separate control, though DLP may trigger encryption as an enforcement action. Option C is incorrect because DLP augments, rather than replaces, existing security controls like firewalls, IAM, and endpoint protection. Option E is too broad — DLP supports compliance with specific data-handling regulations but does not by itself ensure compliance with all regulations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypt all data in transit

    Why it's wrong here

    Encrypting data in transit protects confidentiality against interception, but DLP objectives centre on discovering, monitoring and blocking sensitive data movement across endpoints, networks and cloud. Transport encryption is a cryptographic control, applicable when data must traverse untrusted networks.

  • ✓

    Identify and classify sensitive data

    Why this is correct

    A DLP strategy must first discover where sensitive data resides and label it by classification, since policy enforcement, blocking and reporting all depend on knowing which content is regulated or confidential before any protective control can be applied.

  • ✗

    Replace all existing security controls

    Why it's wrong here

    DLP augments existing controls by inspecting and blocking sensitive data flows; it does not supersede endpoint, network or access controls. Replacement suits technology refresh decisions where a legacy control is decommissioned, not the layered monitoring a DLP strategy adds.

  • ✓

    Monitor and control data movement across endpoints

    Why this is correct

    DLP enforces policy at the movement layer, watching endpoints, email, cloud uploads and removable media, then blocking, quarantining or alerting when classified data crosses an approved boundary. This satisfies the objective of controlling data movement.

  • ✗

    Ensure compliance with all regulations

    Why it's wrong here

    Regulatory compliance is an outcome DLP can support, not a primary objective; DLP exists to identify and prevent unauthorised disclosure of sensitive data. Framing compliance as the objective suits governance and audit programmes, where mapping controls to specific regulatory clauses is the actual task.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.