easyMultiple ChoiceObjective-mapped
CCSP Practice Question: An enterprise uses a cloud access security broker…
An enterprise uses a cloud access security broker (CASB) to protect data in cloud applications. They want to prevent users from uploading files containing credit card numbers to a cloud storage service. Which CASB feature should be configured?
⚠ Common exam trap
Many candidates confuse user activity monitoring (which logs behavior) with DLP (which enforces content-based policies), or they assume encryption alone can prevent data leakage, not realizing encryption protects data in transit but does not inspect or block the data itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data loss prevention (DLP) policies
Data loss prevention (DLP) policies are the correct CASB feature because they allow the enterprise to define content inspection rules that scan files for sensitive data patterns, such as credit card numbers (matching Luhn algorithm or regex patterns like those in PCI DSS). When a match is detected, the CASB can block the upload, quarantine the file, or trigger an alert, directly preventing data exfiltration to the cloud storage service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encryption in transit settings
Why it's wrong here
Encryption does not block content.
- ✗
User activity monitoring
Why it's wrong here
Monitoring only records, not prevent.
- ✗
Single sign-on (SSO) integration
Why it's wrong here
SSO does not inspect content.
- ✓
Data loss prevention (DLP) policies
Why this is correct
DLP scans content and can block uploads containing sensitive data.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.