easyMultiple Select
SSCP Practice Question: Which THREE of the following are data loss…
Which THREE of the following are data loss prevention (DLP) controls that can be implemented to protect sensitive data?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypt sensitive data both at rest and in transit
Option B is correct because encryption of sensitive data at rest (e.g., AES-256 on disks/databases) and in transit (e.g., TLS 1.2+) is a core DLP control that renders intercepted or exfiltrated data unreadable, directly preventing unauthorized disclosure. Option C is correct because endpoint DLP agents enforce policies at the source by inspecting and blocking unauthorized transfers via channels such as USB, email, clipboard, and cloud uploads, which is a primary DLP enforcement mechanism. Option D is correct because data classification with sensitivity labels (e.g., Public, Internal, Confidential, Restricted) is the foundational DLP step that identifies what needs protection and drives which handling, encryption, and blocking policies apply. Option A does not belong because strong passwords are an access-control/authentication measure (identity protection), not a control that detects or prevents sensitive data from leaving the organization. Option E does not belong because blocking all outbound traffic via firewalls is a blunt network availability control, not a data-aware DLP control, and it would break legitimate business communications rather than selectively protect sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require strong passwords for all user accounts
Why it's wrong here
Strong passwords authenticate users; they neither inspect data nor block its movement outside the organisation. DLP controls identify and prevent sensitive data leaving through channels such as email, endpoints or cloud uploads. Password policy is an access control, correct for reducing credential compromise, not data exfiltration.
- ✓
Encrypt sensitive data both at rest and in transit
Why this is correct
Encrypting sensitive data at rest and in transit renders intercepted or exfiltrated content unreadable, acting as a DLP control that limits exposure even when other safeguards fail. This satisfies the requirement to protect sensitive data across both storage and transmission states.
- ✓
Deploy endpoint DLP agents to monitor and block unauthorized data transfers
Why this is correct
Endpoint DLP agents inspect data in use on the device, intercepting transfers to USB storage, email, or cloud uploads and blocking those matching policy. This directly satisfies the requirement to prevent unauthorised data movement at the endpoint, the last point where sensitive data can leave the organisation's control.
- ✓
Classify data based on sensitivity and apply appropriate labels
Why this is correct
Labelling data by sensitivity underpins DLP enforcement: classification metadata lets policies identify which content warrants protection and apply handling restrictions. Without accurate labels, monitoring and blocking rules cannot distinguish sensitive records from ordinary files, so this control satisfies the need to define what must be protected.
- ✗
Implement network firewalls to block all outbound traffic
Why it's wrong here
Blocking all outbound traffic is a network availability control, not DLP; it cannot distinguish sensitive data from legitimate traffic and breaks business operations. DLP inspects content and blocks transfers matching policy. A firewall blocking selected egress is correct for restricting outbound connectivity, not for classifying data.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.