Courseiva
hardMultiple SelectObjective-mapped

CISSP Practice Question: Which THREE of the following are valid…

Which THREE of the following are valid considerations when implementing data loss prevention (DLP) controls to protect sensitive data? (Select three.)

⚠ Common exam trap

Watch out — candidates often assume DLP must be all-encompassing (e.g., blocking all transfers or integrating with every app), but the CISSP emphasizes risk-based, balanced controls that include user awareness and layered monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

User training to reduce false positives and increase acceptance

User training is a critical component of a successful DLP implementation. Without proper training, users may inadvertently trigger false positives by mishandling data or may attempt to bypass controls they perceive as overly restrictive. Training helps users understand classification labels and proper data handling procedures, reducing the operational burden on security teams and increasing overall acceptance of DLP policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Integration with all third-party applications

    Why it's wrong here

    Integrating Data Loss Prevention (DLP) solutions with all third-party applications is generally impractical and often unnecessary. DLP operates effectively at various layers, such as network egress points, endpoint agents, or storage repositories, to monitor and control data flow without requiring deep, custom integration with every single application. Attempting universal integration would introduce significant complexity, cost, and potential compatibility issues, hindering deployment and maintenance rather than enhancing security.

  • User training to reduce false positives and increase acceptance

    Why this is correct

    Effective user training is a critical consideration for successful Data Loss Prevention (DLP) implementation. Educating users on what constitutes sensitive data, acceptable data handling practices, and the purpose of DLP policies helps significantly reduce the occurrence of false positives. This understanding also fosters user acceptance and compliance, minimizing frustration and workarounds when legitimate business activities are temporarily flagged, ultimately improving the overall effectiveness and adoption of the DLP solution.

  • Monitoring of data in use, in motion, and at rest

    Why this is correct

    A robust Data Loss Prevention (DLP) strategy necessitates comprehensive monitoring across all three states of data: data at rest (stored on servers, databases, endpoints), data in motion (transmitting over networks, email, cloud services), and data in use (accessed or processed by applications or users). This holistic coverage ensures that sensitive information is protected throughout its lifecycle, preventing unauthorized disclosure or exfiltration regardless of its current operational state or location within the enterprise environment.

  • Data classification schemes to identify sensitive data

    Why this is correct

    Establishing clear and consistent data classification schemes is a foundational prerequisite for any effective Data Loss Prevention (DLP) program. These schemes enable the organization to accurately identify, label, and categorize sensitive information based on its criticality, regulatory requirements, and business impact. Without precise classification, DLP solutions lack the necessary intelligence to differentiate between permissible and prohibited data transfers, leading to either excessive false positives or critical data leakage.

  • Blocking all data transfers to external devices

    Why it's wrong here

    Indiscriminately blocking all data transfers to external devices, such as USB drives, cloud storage, or personal email, is an overly restrictive and impractical approach for Data Loss Prevention (DLP). While it might prevent some data leakage, it severely impedes legitimate business operations, collaboration, and productivity, leading to significant user frustration and potential workarounds. Effective DLP aims for selective enforcement based on data classification and policy, allowing authorized transfers while preventing unauthorized ones, balancing security with operational necessity.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.