Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium
A global pharmaceutical company is conducting extensive research and development (R&D) on new drug formulations. This involves highly sensitive intellectual property (IP) that must be protected from both external threats and insider risks. The company operates a hybrid IT environment, and the cybersecurity architect needs a GRC technical strategy that ensures the integrity and confidentiality of this IP across all data states (at rest, in transit, in use). Which approach is MOST comprehensive for this scenario?
- ADeploying a robust Data Loss Prevention (DLP) system integrated with Information Rights Management (IRM).
- BImplementing endpoint detection and response (EDR) solutions across all workstations.
- CEstablishing a comprehensive Security Information and Event Management (SIEM) system.
- DUtilizing advanced persistent threat (APT) protection at the network perimeter.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploying a robust Data Loss Prevention (DLP) system integrated with Information Rights Management (IRM).
The combination of Data Loss Prevention (DLP) and Information Rights Management (IRM) offers the most comprehensive protection for sensitive IP across all data states. DLP prevents unauthorized exfiltration, while IRM controls access and usage of the data itself, even after it leaves the organization's direct control.
Why the other options are wrong
- B. EDR focuses on detecting and responding to threats on endpoints but doesn't inherently control how sensitive data is used or prevent its unauthorized sharing once it leaves the endpoint.
- C. A SIEM aggregates security logs for monitoring and alerting but does not directly enforce data protection policies or control data usage.
- D. APT protection at the perimeter is essential for external threats but does not address insider risks or protect data once it is inside the network or in use.
DLP + IRM Integration
Integrating Data Loss Prevention (DLP) with Information Rights Management (IRM) creates a powerful defense that prevents unauthorized data outflow and maintains control over data usage even when it's shared.
- DLP prevents data exfiltration.
- IRM controls data access and usage post-distribution.
- Encrypts and enforces policies on sensitive files.
Memory trick: To protect IP everywhere, DLP guards the gate, IRM locks the content.