Exam CISA All QuestionsBrowse all questions from this exam
Question 560

Which of the following is the BEST control to prevent the transfer of files to external parties through instant messaging (IM) applications?

    Correct Answer: B

    Application level firewalls can be configured to block specific types of traffic, such as file transfers, while allowing other types of traffic. This makes them the best control to prevent the transfer of files to external parties through instant messaging applications. File-level encryption does not prevent the transfer; it only secures the files during transmission. An instant messaging policy is a guideline, not a technical control, and FTP is a protocol for transferring files, not a method to prevent transfers.

Discussion
MunaMOption: B

I think answer is B because it's asking to prevent the transfer of files so it has to be stopped. Application level firewall should be able to do it.

cidigiOption: C

How A is the correct answer here. By encrypting something doesn't stop it from being transferred.. Who provides these answers??

m4s7erOption: B

answer is B

Deeplaxmi

i also think B could be right answer

RS66Option: C

Not A, encryption won't stop transfer... Not B, App FW will stop the IM app, which is not our goal It is C

SwallowsOption: C

While file-level encryption (option A) can help protect the confidentiality of files during transmission, it does not specifically prevent the transfer of files to external parties through IM applications. Encryption ensures that files are securely transmitted, but it does not control whether files are sent externally.

3008Option: B

B is correct. example.. WAF.. deny rule of file

oldmagicOption: C

Correct answer is C. B is not a solution, app level firewall is not a DLP solution. If IM is allowed in the org, app level firewall wont prevent sharing sensitive files over IM. What you need is a DLP solution, but that is not part of the answers, so Policy is the next best choice.

EBTURKOption: B

application level firewalls can be configured to block specific types of traffic, such as file transfers, while allowing other types of traffic

hibilly125Option: B

should be B, A is not preventive measure.