Courseiva
Security OperationshardMultiple ChoiceObjective-mapped

CISSP Security Operations Practice Question

An organization's data loss prevention (DLP) solution is configured to block emails containing credit card numbers. This is an example of which type of DLP control?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Network DLP

Network DLP monitors and controls data in motion, such as email traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Classification-based DLP

    Why it's wrong here

    Classification-based DLP is not a distinct type of DLP solution but rather a fundamental capability or methodology employed *by* DLP solutions. It involves identifying sensitive data through predefined labels, patterns (e.g., regex for PII), or content analysis, which then informs the enforcement policies of network, endpoint, or cloud DLP systems. Therefore, it describes *how* data is identified, not *where* the DLP operates.

  • Network DLP

    Why this is correct

    Network DLP solutions are strategically deployed at network egress points, internal network segments, or as email gateways to monitor and analyze data in transit. They inspect network traffic, including email communications, web uploads, and file transfers, for sensitive content based on predefined policies, preventing unauthorized data exfiltration or policy violations before data leaves the organization's controlled network perimeter.

  • Cloud DLP

    Why it's wrong here

    Cloud DLP specifically targets data residing within or transiting to/from cloud environments, such as Software-as-a-Service (SaaS) applications, Infrastructure-as-a-Service (IaaS) storage, or Platform-as-a-Service (PaaS) databases. It integrates with cloud service providers' APIs or acts as a Cloud Access Security Broker (CASB) to enforce policies on data stored in or shared via cloud services, rather than monitoring general on-premise network traffic.

  • Endpoint DLP

    Why it's wrong here

    Endpoint DLP operates by installing agents directly on user workstations, laptops, servers, or mobile devices. These agents monitor and control data interactions at the source, such as copying files to USB drives, printing documents, uploading to personal cloud storage, or transferring data via local applications. Its primary focus is preventing data loss directly from the device itself, irrespective of network connectivity.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.