Courseiva
Security Operations →mediumMultiple Choice

CISSP Security Operations Practice Question

A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?

⚠ Common exam trap

A common mix-up: candidates confuse 'monitoring email attachments' with endpoint-based controls, but the key distinction is that Network DLP inspects data in motion across the network, whereas Endpoint DLP focuses on local device actions like saving to USB or printing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network DLP

Network DLP monitors data in motion by inspecting network traffic, such as email attachments, as they traverse the network perimeter. This is the correct type because the scenario explicitly describes monitoring email attachments, which are transmitted over the network, and Network DLP is designed to inspect SMTP, HTTP, FTP, and other protocols for sensitive content at the network layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Classification-based controls

    Why it's wrong here

    Classification-based controls label and tag data so policies can act on sensitivity, but they do not themselves inspect email attachments in transit. It is tempting because labels feed DLP rules, yet the question asks which DLP type performs the monitoring, and that is network DLP at the gateway.

  • ✗

    Cloud DLP

    Why it's wrong here

    Cloud DLP inspects data within SaaS applications and cloud storage APIs, not SMTP attachments crossing the corporate mail gateway. It is tempting because it covers cloud-hosted mail such as Microsoft 365, but the scenario describes gateway monitoring of outbound email, which is network DLP.

  • ✓

    Network DLP

    Why this is correct

    Monitoring email attachments in transit for sensitive data inspects network traffic flows, which is network DLP. Endpoint DLP would inspect data on devices, and storage DLP would scan data at rest rather than email in transit.

  • ✗

    Endpoint DLP

    Why it's wrong here

    Endpoint DLP inspects data at rest or in use on the host device, so it cannot monitor attachments traversing the mail server. It is tempting because agents do watch file copies and uploads, but email-attachment inspection at the gateway is the correct choice when traffic leaves the network.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.