Courseiva
mediumMultiple Select

CRISC Practice Question: Which TWO controls are most effective for…

Which TWO controls are most effective for reducing the risk of data leakage from endpoints in a remote work environment?

⚠ Common exam trap

ISACA often tests the misconception that a VPN provides comprehensive data protection, but in reality it only secures data in transit, not data at rest or data in use on the endpoint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement Data Loss Prevention (DLP) software.

Option B, implementing Data Loss Prevention (DLP) software, is correct because DLP solutions inspect data in use, in motion, and at rest, applying content-aware policies (regex, keywords, file fingerprints) to block or quarantine sensitive data from being exfiltrated via email, USB, cloud uploads, or clipboard on remote endpoints. Option D, requiring full-disk encryption on all laptops, is correct because technologies like BitLocker, FileVault, or LUKS with TPM/PIN protect data at rest, ensuring that if a remote worker's laptop is lost or stolen, the stored data cannot be read without the decryption key, directly reducing leakage risk. Option A, phishing simulations, primarily reduces credential-theft and malware risk through user awareness, not endpoint data exfiltration. Option C, complex password policies for local accounts, hardens authentication against brute-force but does not prevent a legitimate user or malware from copying data out. Option E, a VPN, encrypts data in transit and hides traffic from local networks, but it does not stop an authorized endpoint from leaking data to unauthorized destinations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct regular phishing simulation campaigns.

    Why it's wrong here

    Phishing simulations reduce the likelihood of credential theft and malware entry, but they do not stop data leaving an endpoint once access exists. Endpoint data-leakage risk needs controls such as DLP, device restrictions or endpoint agents. Simulations are tempting because user awareness genuinely lowers incident rates, and they would be correct for reducing social-engineering susceptibility.

  • ✓

    Implement Data Loss Prevention (DLP) software.

    Why this is correct

    DLP software inspects endpoint egress content and blocks sensitive data transfers, directly satisfying the remote-work leakage constraint where perimeter controls cannot see off-network traffic. It enforces policy on data in use and in motion regardless of location.

  • ✗

    Enforce complex password policies for local accounts.

    Why it's wrong here

    Complex local-account passwords govern authentication strength, not data movement; they cannot stop a user copying, emailing or uploading files from an endpoint. Password policy is the right control when the risk is credential compromise or brute-force against local accounts, but endpoint data leakage needs controls such as DLP or disk encryption.

  • ✓

    Require full-disk encryption on all laptops.

    Why this is correct

    Full-disk encryption renders data unreadable if a remote laptop is lost or stolen, addressing the physical-theft vector that remote work amplifies. It protects data at rest on the endpoint, complementing controls that govern data in motion.

  • ✗

    Use a VPN for all remote connections.

    Why it's wrong here

    A VPN encrypts data in transit between endpoint and network, protecting against interception on untrusted links. It does not control what data leaves the endpoint itself, such as copying to USB or personal cloud. It is tempting because remote connectivity is a genuine requirement, and a VPN would be correct for securing traffic over public networks.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.