CISSP Practice Question: When implementing data loss prevention (DLP) controls, which approach provides the most…
Published August 27, 2026 · Free daily CISSP practice question
When implementing data loss prevention (DLP) controls, which approach provides the most comprehensive protection?
Correct Answer: D. A combination of network, endpoint, and storage-based DLP
Explanation (CISSP Manager Logic):
Effective data protection requires a defense-in-depth strategy that covers data in all three states: at rest, in transit, and in use. Relying on a single control creates visibility gaps that increase the risk of exfiltration and regulatory non-compliance.
By implementing this solution, you:
- Achieve comprehensive visibility across the entire data lifecycle.
- Mitigate risks from both external transfers and internal endpoint actions.
- Align security architecture with the principle of layered defense.
While the other options are relevant, they fall short because:
- A: Network-based DLP cannot monitor data at rest or local transfers to encrypted removable media.
- B: Endpoint-based DLP fails to capture data moving through non-endpoint network channels or cloud-to-cloud transfers.
- C: Storage-based DLP only identifies sensitive data at rest and does not prevent active exfiltration during transit.
Think like a manager:
Managers must prioritize holistic risk management over siloed solutions to ensure total asset visibility and business resilience.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial