CISSP Security Operations Practice Question
A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?
⚠ Common exam trap
CISSP often tests whether candidates confuse DLP control categories with unrelated security controls — the trap is selecting plausible-sounding but non-standard options like 'Application DLP' or 'Physical DLP' instead of the three canonical types (network, endpoint, cloud).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network DLP
Network DLP (B) is correct because it monitors and inspects data in transit at network egress points such as email gateways, web proxies, and firewalls, typically using deep packet inspection to detect sensitive data leaving the perimeter. Cloud DLP (C) is correct because it applies policy enforcement to data stored in or moving through SaaS, IaaS, and PaaS environments via APIs and CASB integrations, covering cloud storage, email, and collaboration apps. Endpoint DLP (D) is correct because it runs agents on workstations and servers to control data at rest and in use, monitoring file operations, USB/removable media, clipboard, printing, and screen capture. Application DLP and Physical DLP are not standard DLP control categories: application-level enforcement is generally a function within endpoint or network DLP, and physical controls (locked cabinets, badge access, media destruction) belong to physical security rather than DLP technology classifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application DLP
Why it's wrong here
Application DLP is not a recognized or standard classification within the cybersecurity industry's common taxonomy for Data Loss Prevention solutions. DLP is fundamentally concerned with data's state (at rest, in motion, in use) and its deployment location (network, endpoint, cloud), rather than being categorized by individual application integration. While applications may be sources or destinations for sensitive data, and might integrate with broader DLP systems, "Application DLP" does not represent a distinct, standalone deployment type.
- ✓
Network DLP
Why this is correct
Network DLP systems are strategically positioned at key network egress points, such as internet gateways or between network segments, to inspect all data traversing the network perimeter. This deployment type actively monitors data "in motion" by analyzing network traffic, including email, web protocols, and file transfers, for sensitive content that violates predefined organizational policies. Its primary function is to prevent unauthorized data exfiltration before it leaves the controlled network environment.
- ✓
Cloud DLP
Why this is correct
Cloud DLP solutions are specifically designed to protect sensitive data residing within or transiting through various cloud environments, encompassing Software-as-a-Service (SaaS) applications, Infrastructure-as-a-Service (IaaS) storage, and Platform-as-a-Service (PaaS) databases. These systems often integrate directly with cloud service providers via APIs or act as cloud access security brokers (CASBs) to monitor, classify, and protect data at rest and in use within the cloud. This ensures compliance and prevents data loss in environments outside the traditional on-premise perimeter.
- ✓
Endpoint DLP
Why this is correct
Endpoint DLP agents are installed directly on individual user devices, including workstations, laptops, and mobile devices, providing granular control and monitoring capabilities at the source of data creation and access. This deployment type monitors data "at rest" on the device's storage, "in use" during operations like copy/paste or printing, and "in motion" when data is transferred via USB drives, email, or other local channels. It is crucial for preventing data loss from devices that may operate outside the corporate network.
- ✗
Physical DLP
Why it's wrong here
The concept of "Physical DLP" is a misnomer and does not represent a standard or recognized category within the domain of Data Loss Prevention. DLP is a cybersecurity discipline focused on logical controls, policies, and technologies to prevent sensitive data from leaving an organization's control through digital channels. Physical security, conversely, deals with protecting tangible assets, facilities, and access points from unauthorized physical intrusion or theft, operating on an entirely different set of principles and mechanisms.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.