mediumMultiple Choice
CISSP Practice Question: A financial institution is implementing a data…
A financial institution is implementing a data loss prevention (DLP) solution to protect customer financial information. The DLP system must detect and block the transmission of credit card numbers via email. Which of the following is the BEST approach to ensure accurate detection while minimizing false positives?
⚠ Common exam trap
Candidates may choose Option C, thinking simple pattern matching is sufficient, but they overlook the high rate of false positives from non-credit-card digit sequences (like phone numbers, serial numbers, or internal IDs) that do not pass the Luhn checksum.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a regular expression that validates the Luhn algorithm in addition to pattern matching
Combining a regular expression for credit card number patterns with Luhn algorithm validation significantly reduces false positives. The regular expression identifies potential matches (e.g., 16-digit patterns), and the Luhn algorithm checks the mathematical validity of the checksum. This dual-layer approach is a standard DLP best practice for accurately detecting sensitive data like credit card numbers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply a regular expression that validates the Luhn algorithm in addition to pattern matching
Why this is correct
This approach significantly enhances the accuracy of detecting actual credit card numbers within data streams. A regular expression first identifies sequences that structurally resemble credit card numbers (e.g., 13-19 digits). Subsequently, applying the Luhn algorithm, a mathematical checksum formula, validates if the number is mathematically plausible as a legitimate credit card number, drastically reducing false positives from random number sequences that merely match the visual pattern. This two-stage validation is highly effective in robust Data Loss Prevention (DLP) systems.
- ✗
Hash all outbound emails and compare against a database of known credit card hashes
Why it's wrong here
Hashing credit card numbers before comparison is fundamentally flawed for effective DLP. Hashing is a one-way function that prevents the detection of variations (e.g., a single digit change) or new, previously unseen credit card numbers, which is a primary goal of proactive DLP. Moreover, relying on a database of known hashes would only detect already compromised or specifically identified numbers, failing to protect against new data exfiltration. This method would also risk blocking legitimate emails due to hash collisions or if the database was incomplete.
- ✗
Use a simple regular expression matching patterns like '\d{4}-\d{4}-\d{4}-\d{4}'
Why it's wrong here
While a simple regular expression like '\d{4}-\d{4}-\d{4}-\d{4}' can identify sequences of 16 digits, it lacks the necessary specificity for accurate credit card detection. This pattern would indiscriminately flag any 16-digit number formatted with hyphens, such as internal employee IDs, product codes, or even phone numbers, as a credit card number. This high rate of false positives would overwhelm security analysts with irrelevant alerts and lead to unnecessary blocking of legitimate business communications, diminishing the DLP system's utility.
- ✗
Rely on machine learning classifiers trained on past credit card data
Why it's wrong here
While machine learning (ML) is powerful for many tasks, relying solely on classifiers for detecting highly structured, sensitive numeric data like credit card numbers presents significant challenges. ML models might struggle with the precise, deterministic nature of credit card numbers, potentially missing subtle patterns or requiring extensive, continuously updated training data to adapt to new card types or formats. Furthermore, the "black box" nature of some ML models can make it difficult to audit why a specific detection occurred, which is crucial for compliance and incident response in financial institutions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.