CISSP Security Operations Practice Question
A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network DLP
Network DLP inspects traffic at egress points to prevent unauthorized data transmission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Network DLP
Why this is correct
Network DLP solutions are strategically deployed at network egress points, such as internet gateways or email servers, to inspect all outbound network traffic in real-time. This technology analyzes data streams for sensitive information based on predefined policies, identifying and preventing unauthorized transmission of confidential data via protocols like HTTP, HTTPS, FTP, and SMTP. Its primary function is to stop data leakage as it attempts to leave the organizational boundary.
- ✗
Cloud DLP
Why it's wrong here
Cloud DLP specifically targets data residing within or transiting through cloud environments, including Software-as-a-Service (SaaS) applications, Infrastructure-as-a-Service (IaaS) platforms, and Platform-as-a-Service (PaaS) offerings. It integrates with cloud service providers' APIs to monitor data at rest in cloud storage, data in use within cloud applications, and data in motion between cloud services, ensuring compliance and preventing exposure of sensitive information in these distributed environments.
- ✗
Endpoint DLP
Why it's wrong here
Endpoint DLP operates directly on individual workstations, servers, and mobile devices, monitoring user actions and data movement at the source. It tracks file access, copy operations, printing, USB transfers, and application usage, enforcing policies to prevent sensitive data from being copied to unauthorized media or applications. While effective for local control, it may not intercept data that bypasses the endpoint agent or is transmitted directly from network appliances.
- ✗
Classification-based controls
Why it's wrong here
Classification-based controls refer to the policies and rules derived from an organization's data classification scheme, which categorizes data by sensitivity level (e.g., public, internal, confidential). These controls are foundational for DLP, dictating what data is protected and how it should be handled, but they are not a specific type of DLP technology or deployment model. Instead, they define the criteria that Network, Cloud, or Endpoint DLP solutions use to identify and protect sensitive information.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.