Courseiva
hardMultiple ChoiceObjective-mapped

CCSP Practice Question: A multinational corporation uses a cloud CASB to…

A multinational corporation uses a cloud CASB to enforce data loss prevention (DLP) policies across SaaS applications. The security team discovers that sensitive data is being exfiltrated via encrypted traffic that the CASB cannot inspect. What is the most effective design change to mitigate this risk?

⚠ Common exam trap

ISC2 often tests the misconception that blocking or disabling encryption is a valid DLP solution, when in fact the correct approach is to use interception that maintains encryption end-to-end while enabling inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy a forward proxy with SSL/TLS interception capabilities.

A forward proxy with SSL/TLS interception capabilities allows the CASB to decrypt, inspect, and re-encrypt traffic, enabling DLP policy enforcement on data in transit. This design change addresses the root cause—encrypted traffic bypassing inspection—without breaking application functionality or security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement user training to prevent data exfiltration.

    Why it's wrong here

    Incorrect: Training alone cannot prevent exfiltration over encrypted channels; technical controls are needed.

  • Block all encrypted traffic at the network perimeter.

    Why it's wrong here

    Incorrect: This would break many legitimate applications and is not a viable solution.

  • Deploy a forward proxy with SSL/TLS interception capabilities.

    Why this is correct

    Correct: This enables decryption and inspection of traffic while maintaining end-to-end security.

  • Disable TLS/SSL encryption for all sensitive data transfers.

    Why it's wrong here

    Incorrect: Disabling encryption exposes data to interception and is a security risk.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.