mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: Uses a data loss prevention (DLP) system to…
An organization uses a data loss prevention (DLP) system to monitor outbound emails. Which data classification type would the DLP most likely use to detect sensitive information leaving the network?
⚠ Common exam trap
ISC2 often tests the distinction between context-based and content-based classification, where candidates mistakenly choose context-based because they confuse 'monitoring outbound emails' with analyzing sender/recipient metadata rather than the actual data content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Content-based classification
Content-based classification inspects the actual data within outbound emails—such as credit card numbers, social security numbers, or other regex-defined patterns—to detect sensitive information. DLP systems rely on content analysis (e.g., regular expressions, exact data matching, or fingerprinting) to identify and block policy violations, making this the correct classification type for detecting sensitive data leaving the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Context-based classification
Why it's wrong here
Context-based classification in Data Loss Prevention (DLP) relies on metadata and environmental attributes surrounding the data, such as the sender, recipient, file name, application used, or network protocol. While these contextual elements are crucial for applying DLP policies and determining if sensitive data is being mishandled, they do not directly perform the initial identification and categorization of the data as sensitive information based on its intrinsic content. Therefore, a DLP system primarily uses other methods to classify the data itself.
- ✓
Content-based classification
Why this is correct
Content-based classification is a fundamental capability of Data Loss Prevention (DLP) systems, directly examining the actual data payload to identify sensitive information. This method employs techniques like keyword matching, regular expressions (e.g., for credit card numbers or Social Security numbers), exact data matching (EDM) against known sensitive datasets, and machine learning to detect patterns and specific data types. By analyzing the content itself, DLP can accurately classify data as sensitive and enforce policies to prevent its unauthorized exfiltration or misuse.
- ✗
User-based classification
Why it's wrong here
User-based classification is not a recognized or standard method for a Data Loss Prevention (DLP) system to classify data as sensitive. While users might tag or label data, or DLP policies might be applied based on user identity or group membership, the DLP system itself does not inherently classify data's sensitivity based solely on the user interacting with it. The classification of the data's sensitivity is independent of the user, focusing instead on the data's inherent characteristics.
- ✗
Role-based classification
Why it's wrong here
Role-based classification is primarily an access control mechanism, where permissions to access or manipulate data are granted based on a user's assigned organizational role, not on the inherent sensitivity or content of the data itself. While DLP policies can leverage role-based access control (RBAC) information to determine who is authorized to perform certain actions with already classified sensitive data, RBAC does not perform the initial classification of data to identify it as sensitive for DLP purposes.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.