An organization needs to prevent customer service representatives from copying sensitive customer database files to unauthorized USB flash drives attached to local workstations. Which data protection control should the security analyst implement to enforce this restriction?
- Endpoint Data Loss Prevention (DLP)Answer
- BStorage Area Network (SAN) LUN masking
- CAsymmetric RSA key pairs for bulk file encryption
- DDeception honeypots deployed on the storage VLAN
Answer
Endpoint Data Loss Prevention (DLP) should be implemented to monitor and block unauthorized file transfers to removable USB storage.
Endpoint Data Loss Prevention (DLP) software runs directly on user workstations to inspect data in use and enforce policies that block unauthorized operations, such as copying sensitive files containing Personal Identifiable Information (PII) to removable USB media.
Step-by-Step Solution
Key Concept
Endpoint Data Loss Prevention (DLP)