Question

Difficulty: EasyData Protection and Storage Security Architecture

An organization needs to monitor and prevent sensitive data, such as personally identifiable information (PII), from being copied onto unauthorized USB storage devices or uploaded to unauthorized web services by internal users. Which of the following data protection solutions is designed to inspect file contents and enforce access policies based on data classification rules?

  1. A
    Full Disk Encryption (FDE)
  2. B
    Hardware Security Module (HSM)
  3. Data Loss Prevention (DLP)Answer
  4. D
    Storage Area Network (SAN) Zoning

Answer

Data Loss Prevention (DLP) is the correct control because it inspects file contents against policy rules to identify sensitive data and restrict unauthorized data transfers.
Data Loss Prevention (DLP) tools dynamically inspect file content and metadata against organizational security policies, allowing administrators to block sensitive data transfers to removable storage devices or external web destinations.

Step-by-Step Solution

1
Analyze the operational requirement.
The requirement calls for inspecting file contents to identify sensitive data and preventing unauthorized copying to external storage or cloud destinations.
Identifying sensitive data during user activities requires content-aware inspection.
2
Evaluate available storage security technologies.
Data Loss Prevention (DLP) operates by analyzing data pattern signatures and classifications to enforce contextual copy and upload restrictions.
Other storage controls like FDE, HSM, or SAN zoning protect physical volumes, manage keys, or isolate network storage rather than monitoring endpoint content movement.

Key Concept

Data Loss Prevention (DLP) controls for data in use and data in motion
Estimated Time:45s
Rate this question