CCSP Exam QuestionsBrowse all questions from this exam

CCSP Exam - Question 227


Which of the following is NOT one of the main intended goals of a DLP solution?

Show Answer
Correct Answer: A

Data Loss Prevention (DLP) solutions are intended to prevent data breaches, ensure regulatory compliance, and manage and minimize risk associated with data loss. These solutions focus on monitoring and protecting sensitive data from being leaked, whether through intentional or unintentional actions. While they can help in mitigating risks from malicious insiders, this is not their primary goal. Showing due diligence is not a main intended goal of a DLP solution, as it is more of a concept related to legal liabilities and responsibilities, rather than a direct objective of DLP systems.

Discussion

10 comments
Sign in to comment
dhiru
Oct 29, 2021

But DLP is an effective solution to prevent malicious insider/user from sending sensitive data out of the network.

Guest4768
Nov 1, 2021

It is difficult to cover ALL data fraud cases by insiders with DLP. B is partially correct, and others are fully correct, so B is the answer.

kjjcraigskel
Apr 15, 2022

DLP doesn't prevent malicious insiders. It hinders them.

xaccan
Apr 6, 2023

Malicious insider does not explicitly mean leaking sensitive data outside the company, it is a general term.

Biden
Aug 9, 2023

Question is "NOT one of the main intended goals of a DLP solution?" !! Whats does "Showing Due Diligence" have anything to do with DLP? Shudnt this be the correct answer ?

akg001
Nov 19, 2023

A. Showing due diligence

akg001Option: A
Nov 19, 2023

A. Showing due diligence

Loveguitar
Nov 22, 2024

The answer is correct (Insider threat prevention is not among the goals of a DLP system). The goals of a DLP strategy for an organization are to manage and minimize risk, maintain compliance with regulatory requirements, and show due diligence on the part of the application and data owner. Carter, Daniel. CCSP Certified Cloud Security Professional All-in-One Exam Guide, Third Edition (p. 101). McGraw Hill LLC. Kindle Edition.

Pika26Option: B
Oct 23, 2024

B. Preventing malicious insiders

funktribe
Dec 8, 2022

DLP is not a breach detection technology hence B is correct

[Removed]
Jul 6, 2023

"Showing due diligence" to what ? Question/answer is incorrect. DLP is heavily used to protect from insider disclosures. CCSP Official guide says "DLP can protect from malicious disclosure" which would equate malicious insider. DLP goals Additional security Policy enforcement Enhanced monitoring Regulatory compliance

serget12
Apr 13, 2024

I believe the number 1 threat/ security issue has to do with internal risks.

AJ2021Option: A
Apr 25, 2024

Not a very clear question, you could argue for both A & B to be correct, in my opinion A is correct

MaciekMTOption: A
Feb 21, 2025

While a DLP solution does help demonstrate that an organization is taking proactive steps toward data protection (which can be useful in showing due diligence), its primary goals are to prevent unauthorized data exfiltration (including threats from malicious insiders), ensure regulatory compliance, and manage and minimize risk associated with data loss. "Showing due diligence" is more of a legal or reputational benefit rather than a direct technical or operational objective of the DLP solution