Courseiva
Security Operations →easyMultiple Select

CISSP Security Operations Practice Question

A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?

⚠ Common exam trap

CISSP often tests whether candidates confuse DLP control categories with unrelated security controls — the trap is selecting plausible-sounding but non-standard options like 'Application DLP' or 'Physical DLP' instead of the three canonical types (network, endpoint, cloud).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network DLP

Network DLP (B) is correct because it monitors and inspects data in transit at network egress points such as email gateways, web proxies, and firewalls, typically using deep packet inspection to detect sensitive data leaving the perimeter. Cloud DLP (C) is correct because it applies policy enforcement to data stored in or moving through SaaS, IaaS, and PaaS environments via APIs and CASB integrations, covering cloud storage, email, and collaboration apps. Endpoint DLP (D) is correct because it runs agents on workstations and servers to control data at rest and in use, monitoring file operations, USB/removable media, clipboard, printing, and screen capture. Application DLP and Physical DLP are not standard DLP control categories: application-level enforcement is generally a function within endpoint or network DLP, and physical controls (locked cabinets, badge access, media destruction) belong to physical security rather than DLP technology classifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application DLP

    Why it's wrong here

    Application DLP is not a recognized or standard classification within the cybersecurity industry's common taxonomy for Data Loss Prevention solutions. DLP is fundamentally concerned with data's state (at rest, in motion, in use) and its deployment location (network, endpoint, cloud), rather than being categorized by individual application integration. While applications may be sources or destinations for sensitive data, and might integrate with broader DLP systems, "Application DLP" does not represent a distinct, standalone deployment type.

  • ✓

    Network DLP

    Why this is correct

    Network DLP systems are strategically positioned at key network egress points, such as internet gateways or between network segments, to inspect all data traversing the network perimeter. This deployment type actively monitors data "in motion" by analyzing network traffic, including email, web protocols, and file transfers, for sensitive content that violates predefined organizational policies. Its primary function is to prevent unauthorized data exfiltration before it leaves the controlled network environment.

  • ✓

    Cloud DLP

    Why this is correct

    Cloud DLP solutions are specifically designed to protect sensitive data residing within or transiting through various cloud environments, encompassing Software-as-a-Service (SaaS) applications, Infrastructure-as-a-Service (IaaS) storage, and Platform-as-a-Service (PaaS) databases. These systems often integrate directly with cloud service providers via APIs or act as cloud access security brokers (CASBs) to monitor, classify, and protect data at rest and in use within the cloud. This ensures compliance and prevents data loss in environments outside the traditional on-premise perimeter.

  • ✓

    Endpoint DLP

    Why this is correct

    Endpoint DLP agents are installed directly on individual user devices, including workstations, laptops, and mobile devices, providing granular control and monitoring capabilities at the source of data creation and access. This deployment type monitors data "at rest" on the device's storage, "in use" during operations like copy/paste or printing, and "in motion" when data is transferred via USB drives, email, or other local channels. It is crucial for preventing data loss from devices that may operate outside the corporate network.

  • ✗

    Physical DLP

    Why it's wrong here

    The concept of "Physical DLP" is a misnomer and does not represent a standard or recognized category within the domain of Data Loss Prevention. DLP is a cybersecurity discipline focused on logical controls, policies, and technologies to prevent sensitive data from leaving an organization's control through digital channels. Physical security, conversely, deals with protecting tangible assets, facilities, and access points from unauthorized physical intrusion or theft, operating on an entirely different set of principles and mechanisms.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.