ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsHard
A cloud service provider (CSP) is implementing a new security control to prevent data exfiltration. This control analyzes outgoing network traffic for sensitive information based on predefined patterns and keywords, and blocks or quarantines traffic that violates policy. Which preventative measure is being described?
- AData Loss Prevention (DLP)
- BIntrusion Prevention System (IPS)
- CNetwork Access Control (NAC)
- DWeb Application Firewall (WAF)
Show answer & explanationAnswer & explanation
Correct answer: A. Data Loss Prevention (DLP)
The description of analyzing outgoing network traffic for sensitive information (based on patterns/keywords) and blocking/quarantining it to prevent data exfiltration is the core function of Data Loss Prevention (DLP) systems.
Why the other options are wrong
- B. IPS focuses on detecting and preventing network-based attacks and exploits, not specifically sensitive data exfiltration.
- C. NAC controls which devices can connect to a network, not the content of their outgoing traffic for sensitive data.
- D. WAF protects web applications from attacks, primarily inbound, and doesn't focus on general outgoing sensitive data.
Data Loss Prevention (DLP)
Data Loss Prevention (DLP) is a set of tools and processes designed to ensure that sensitive data is not lost, misused, or accessed by unauthorized users. DLP systems classify and protect sensitive information, preventing its unauthorized disclosure.
- Prevents sensitive data exfiltration.
- Analyzes data in use, in motion, and at rest.
- Uses content inspection, keyword matching, and pattern recognition.
Memory trick: DLP 'Deters Leaking' of sensitive data.