Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
An organization is concerned about insider threats and data exfiltration from endpoints. They want to prevent sensitive documents from being copied to USB drives, uploaded to unauthorized cloud storage, or sent via personal email accounts. Which endpoint security technology is best suited to address these specific concerns?
- ASecurity Information and Event Management (SIEM)
- BEndpoint Detection and Response (EDR)
- CNetwork Access Control (NAC)
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: D. Data Loss Prevention (DLP)
DLP solutions are specifically designed to identify, monitor, and protect sensitive data from unauthorized exfiltration, whether through USB, cloud services, email, or other channels.
Why the other options are wrong
- A. SIEM aggregates and analyzes security logs, which can help detect data exfiltration after it occurs, but it doesn't actively prevent it at the endpoint.
- B. EDR focuses on detecting and responding to advanced threats and malware on endpoints, not primarily preventing data exfiltration.
- C. NAC controls which devices can connect to the network, not how data is handled once a device is connected.
Data Loss Prevention (DLP)
A set of tools and processes used to ensure that sensitive data is not lost, misused, or accessed by unauthorized users, preventing its unauthorized transmission outside the organization.
- Identifies and classifies sensitive data.
- Monitors data in use, in motion, and at rest.
- Enforces policies to prevent data exfiltration.
Memory trick: DLP is the guard dog for your data, keeping it from running away.