hardMultiple Choice
CCSP Practice Question: An enterprise uses a Cloud Access Security Broker…
An enterprise uses a Cloud Access Security Broker (CASB) to monitor cloud application usage. The CASB generates alerts about potential data loss prevention events. What is the primary purpose of the CASB's DLP capabilities?
⚠ Common exam trap
ISC2 often tests the misconception that DLP's primary purpose is to block all sensitive data or to classify data, when in fact it is to enforce granular policies that detect and prevent unauthorized sharing based on context (e.g., user, location, device).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To detect and prevent unauthorized sharing of sensitive data based on policies
The primary purpose of a CASB's DLP capabilities is to enforce policies that detect and prevent unauthorized sharing of sensitive data. This is achieved by inspecting content in transit (e.g., via API or proxy) and applying rules such as blocking, quarantining, or alerting on policy violations. Option C correctly captures this core function of policy-based detection and prevention, which goes beyond simple blocking or classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To block all uploads of sensitive data to cloud apps
Why it's wrong here
DLP capabilities detect and alert on sensitive data flows, not enforce blanket upload blocking; that requires inline proxy enforcement with explicit deny policies. Alerting exists precisely because legitimate transfers occur, so a universal block would break business workflows. Blocking suits environments mandating zero egress of regulated data.
- ✗
To classify data automatically using machine learning
Why it's wrong here
Machine-learning classification supports DLP by labelling content, but the DLP capability's purpose is detecting and reporting policy violations, not building the classifier itself. Classification is an input to detection. Auto-classification would be the answer where the requirement is labelling data assets for governance, not alerting on exfiltration events.
- ✓
To detect and prevent unauthorized sharing of sensitive data based on policies
Why this is correct
CASB DLP inspects traffic and content flowing to cloud services, applying policy rules to identify sensitive data such as PII or credentials and block or alert on its unauthorised sharing, satisfying the requirement to detect and prevent exfiltration via sanctioned and unsanctioned applications.
- ✗
To encrypt data before it is sent to cloud apps
Why it's wrong here
Encryption is performed by the cloud app or client-side tooling, not the CASB's DLP engine, which inspects content in transit for sensitive patterns. A CASB can enforce encryption via API controls, but that is a separate capability from DLP alerting. Encryption fits scenarios requiring confidentiality of data at rest in the SaaS provider.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.