Asset SecurityMedium

CISSP Practice Question: When implementing data loss prevention (DLP) controls, which approach provides the most…

Published August 27, 2026 · Free daily CISSP practice question
When implementing data loss prevention (DLP) controls, which approach provides the most comprehensive protection?
  1. A.Network-based DLP only
  2. B.Endpoint-based DLP only
  3. C.Storage-based DLP only
  4. D.A combination of network, endpoint, and storage-based DLP
Correct answer: D. A combination of network, endpoint, and storage-based DLP

Correct Answer: D. A combination of network, endpoint, and storage-based DLP

Explanation (CISSP Manager Logic):

Effective data protection requires a defense-in-depth strategy that covers data in all three states: at rest, in transit, and in use. Relying on a single control creates visibility gaps that increase the risk of exfiltration and regulatory non-compliance.

By implementing this solution, you:

  • Achieve comprehensive visibility across the entire data lifecycle.
  • Mitigate risks from both external transfers and internal endpoint actions.
  • Align security architecture with the principle of layered defense.

While the other options are relevant, they fall short because:

  • A: Network-based DLP cannot monitor data at rest or local transfers to encrypted removable media.
  • B: Endpoint-based DLP fails to capture data moving through non-endpoint network channels or cloud-to-cloud transfers.
  • C: Storage-based DLP only identifies sensitive data at rest and does not prevent active exfiltration during transit.

Think like a manager:

Managers must prioritize holistic risk management over siloed solutions to ensure total asset visibility and business resilience.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions