hardMultiple ChoiceObjective-mapped
CCSP Practice Question: A multinational corporation uses a cloud CASB to…
A multinational corporation uses a cloud CASB to enforce data loss prevention (DLP) policies across SaaS applications. The security team discovers that sensitive data is being exfiltrated via encrypted traffic that the CASB cannot inspect. What is the most effective design change to mitigate this risk?
⚠ Common exam trap
ISC2 often tests the misconception that blocking or disabling encryption is a valid DLP solution, when in fact the correct approach is to use interception that maintains encryption end-to-end while enabling inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a forward proxy with SSL/TLS interception capabilities.
A forward proxy with SSL/TLS interception capabilities allows the CASB to decrypt, inspect, and re-encrypt traffic, enabling DLP policy enforcement on data in transit. This design change addresses the root cause—encrypted traffic bypassing inspection—without breaking application functionality or security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement user training to prevent data exfiltration.
Why it's wrong here
Incorrect: Training alone cannot prevent exfiltration over encrypted channels; technical controls are needed.
- ✗
Block all encrypted traffic at the network perimeter.
Why it's wrong here
Incorrect: This would break many legitimate applications and is not a viable solution.
- ✓
Deploy a forward proxy with SSL/TLS interception capabilities.
Why this is correct
Correct: This enables decryption and inspection of traffic while maintaining end-to-end security.
- ✗
Disable TLS/SSL encryption for all sensitive data transfers.
Why it's wrong here
Incorrect: Disabling encryption exposes data to interception and is a security risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.