Courseiva
hardMultiple Choice

ISC2 CC Practice Question: Implementing a data loss prevention (DLP) solution

A company is implementing a data loss prevention (DLP) solution. Which strategy BEST balances security and productivity when monitoring outgoing email?

⚠ Common exam trap

ISC2 often tests the concept that DLP is not just about blocking or encrypting data, but about applying policy with context and user feedback to balance security and productivity, leading candidates to mistakenly choose overly restrictive options like B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Alert on policy violations and allow user to override with manager approval

It balances security and productivity by alerting on policy violations while allowing users to override the block with manager approval. This approach ensures that legitimate business communications are not disrupted, while still enforcing DLP policies through a secondary review process. In a DLP solution, this is often implemented via a 'justify and override' workflow, where the user must provide a reason and receive approval from a manager before the email is sent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Log all emails without any alerts

    Why it's wrong here

    Logging every message without alerts produces no enforcement or notification, so a breach continues undetected and the security half of the balance is unmet. It is tempting because passive logging suits forensic auditing and baseline visibility, and would be correct where monitoring only, not prevention, is required.

  • ✗

    Block all emails containing keywords like 'confidential'

    Why it's wrong here

    Keyword blocking quarantines legitimate business mail containing 'confidential', halting workflows and generating false positives that erode productivity. It is tempting because content-based blocking is a genuine DLP control, and would be correct where strict prevention of specific regulated data patterns is the priority.

  • ✗

    Encrypt all outgoing emails automatically

    Why it's wrong here

    Encrypting all outbound mail protects data in transit but does not detect or prevent exfiltration, so the monitoring requirement is unaddressed. It is tempting because encryption is a recognised data-protection control, and would be correct where confidentiality of messages in transit is the objective rather than DLP monitoring.

  • ✓

    Alert on policy violations and allow user to override with manager approval

    Why this is correct

    Alerting on violations while permitting manager-approved overrides satisfies the stem's balance requirement: sensitive data triggers detection, yet business-critical email is not blocked outright. This human-in-the-loop workflow preserves productivity through a documented approval path, unlike hard blocking, which halts legitimate communication, or silent logging, which fails to prevent exfiltration.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.