hardMultiple Choice
CCSP Practice Question: A multinational corporation uses a cloud access…
A multinational corporation uses a cloud access security broker (CASB) to enforce data protection policies across multiple SaaS applications. They discover that sensitive data tagged with 'Confidential' is being shared externally via a file-sharing application. The CASB currently only logs activities. Which action should the security team take to prevent such data loss in the future?
⚠ Common exam trap
ISC2 often tests the distinction between detection (logging) and prevention (blocking), and the trap here is that candidates may choose training (Option C) as a 'best practice' without recognizing that the question explicitly asks for a technical action to prevent data loss, which requires an automated enforcement mechanism like DLP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a DLP policy that automatically blocks sharing of documents with the 'Confidential' label.
A CASB with Data Loss Prevention (DLP) capabilities can enforce real-time policies to block sharing of documents tagged with a specific sensitivity label (e.g., 'Confidential'). Since the CASB currently only logs activities, implementing a DLP policy that automatically blocks the sharing action addresses the root cause—preventing the data loss at the point of egress—rather than merely detecting it after the fact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt all files stored in the file-sharing application.
Why it's wrong here
Encrypting stored files protects data at rest but the CASB cannot stop an authorised user from sharing decrypted content externally. It is tempting because encryption is a core data-protection control, yet it addresses storage confidentiality, not the egress action the CASB must block.
- ✗
Revoke user access to the file-sharing application for all employees.
Why it's wrong here
Revoking access for all employees blocks legitimate business use of the application and is disproportionate, while the CASB should target only Confidential-tagged transfers. It is tempting as a decisive containment step, but the requirement is selective enforcement of data-loss policy, not blanket denial of a sanctioned SaaS service.
- ✗
Train employees on data handling policies.
Why it's wrong here
Training changes human behaviour but enforces nothing automatically, so tagged files can still leave externally. It is tempting because awareness reduces accidental sharing, yet the CASB already detects the activity; the missing control is inline policy enforcement that blocks the transfer rather than relying on user compliance.
- ✓
Implement a DLP policy that automatically blocks sharing of documents with the 'Confidential' label.
Why this is correct
Blocking labelled 'Confidential' documents from external sharing directly addresses the stem's constraint: the CASB only logs, so no enforcement occurs. Inline DLP inspection lets the CASB intercept the upload and apply a block action at the API or proxy layer, converting detection into prevention for that specific label.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.