Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium
A security engineer is configuring a Cisco Secure Web Appliance (WSA) to prevent users from uploading sensitive company documents to unauthorized cloud storage services. The solution needs to identify specific types of data, such as credit card numbers and intellectual property, within HTTP/HTTPS uploads. Which feature of the WSA would be most effective for this requirement?
- AData Loss Prevention (DLP)
- BURL Filtering
- CApplication Visibility and Control (AVC)
- DAdvanced Malware Protection (AMP)
Show answer & explanationAnswer & explanation
Correct answer: A. Data Loss Prevention (DLP)
Data Loss Prevention (DLP) on the Cisco WSA is specifically designed to identify, monitor, and protect sensitive data in motion, preventing unauthorized transmission. It uses predefined or custom policies to detect sensitive information like credit card numbers or intellectual property.
Why the other options are wrong
- B. URL Filtering blocks or allows access to websites based on their category or reputation, but it does not inspect the content of uploads for sensitive data.
- C. AVC identifies and controls applications, but it doesn't granularly inspect the content within application traffic for specific sensitive data patterns.
- D. AMP focuses on detecting and preventing malware, not on identifying and blocking the upload of sensitive company documents.
Data Loss Prevention (DLP)
A set of tools and processes designed to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.
- Identifies sensitive data based on patterns, keywords, or fingerprints.
- Monitors data in motion, at rest, and in use.
- Prevents unauthorized data exfiltration.
Memory trick: Don't Let Private data Out!