CompTIA Security+ (SY0-701)Security OperationsEasy
A security appliance inspects outbound email and automatically blocks messages containing credit card numbers before they leave the network. Which type of tool is being used?
- AIntrusion prevention system (IPS)
- BNetwork access control (NAC) system
- CData loss prevention (DLP) system
- DWeb application firewall (WAF)
Show answer & explanationAnswer & explanation
Correct answer: C. Data loss prevention (DLP) system
DLP systems monitor and control data in motion, at rest, or in use to prevent sensitive information, such as credit card numbers, from leaving the organization without authorization.
Why the other options are wrong
- A. IPS blocks malicious network traffic patterns, not sensitive data content.
- B. NAC controls device access to the network, not content of communications.
- D. A WAF protects web applications from attacks like SQL injection.
Data Loss Prevention (DLP)
A security tool that identifies and blocks unauthorized transmission of sensitive data such as PII, PCI, or intellectual property.
- Monitors data in motion, at rest, and in use
- Can block, quarantine, or alert on policy violations
- Uses pattern matching (e.g., credit card regex)
- Deployed at email gateways, endpoints, and network egress
Memory trick: DLP = Don't Leak Private data.