ISC2 Certified in Cybersecurity (CC)Network SecurityHard

A CISO is concerned about potential data exfiltration from the organization's network. They want to implement a solution that constantly monitors outgoing network traffic for sensitive information (e.g., credit card numbers, intellectual property) and prevents it from leaving the network. Which technology should be recommended?

  1. AIntrusion Detection System (IDS)
  2. BData Loss Prevention (DLP)
  3. CSecurity Information and Event Management (SIEM)
  4. DNetwork Access Control (NAC)
Show answer & explanation

Correct answer: B. Data Loss Prevention (DLP)

Data Loss Prevention (DLP) systems are specifically designed to detect and prevent sensitive data from leaving the organization's network or endpoints. They monitor, identify, and block the transmission of confidential information based on predefined policies and content analysis.

Why the other options are wrong

  • A. IDS detects malicious activity but is not specifically focused on identifying and blocking sensitive data content in transit.
  • C. SIEM aggregates and analyzes security logs and events for threat detection, but its primary function is not to *prevent* data exfiltration in real-time.
  • D. NAC controls who can access the network based on device health and user identity, not the content of data leaving the network.

Data Loss Prevention (DLP)

A set of tools and processes used to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.

  • Monitors, detects, and blocks sensitive data in motion, at rest, and in use.
  • Prevents unauthorized data exfiltration.
  • Enforces compliance regulations (e.g., GDPR, PCI DSS).

Memory trick: DLP is the 'data bouncer' at the network's exit.

More Network Security questions