Protecting Sensitive Data with DLP and Classification

Answer Correct answer: C — Configure Data Loss Prevention (DLP) to enforce policies based on the organization's existing data labeling and classification system to protect sensitive information.

The Chief Information Security Officer wants to put security measures in place to protect PH. The organization needs to use its existing labeling and classification system to accomplish this goal. Which of the following would most likely be configured to meet the requirements?

  1. Tokenization
  2. S/MIME
  3. DLP Correct Answer
  4. MFA

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This tests knowledge of data protection mechanisms, specifically how DLP integrates with data classification to prevent unauthorized exposure or loss of sensitive information like PII/PHI.

The question asks for a security measure to protect sensitive data using existing labeling systems. Data Loss Prevention (DLP) is the correct technology as it enforces policies based on data classification labels.

Candidates often confuse DLP with encryption tools like S/MIME. While S/MIME protects data in transit via email, it does not enforce organizational labeling policies across all data types or locations.

Community Discussion (5 comments)

[Removed] 👍 14 Selected: C
I think that the PH is an error and is supposed to be PHI. DLP prevents people from sending information about PII and PHI and pretects againts data loss. i can see any of the other question fitting.
1403ad2 👍 11 Selected: C
choose C 2024-20-2 On Test and passed with 802
LayinCable 👍 1 Selected: C
Data Loss Prevention. i.e. "To prevent data from being 'lost' or 'stolen' "
scoobysnack209 👍 1
You guys are right, it might be a type since 'PH' in not in the Security+ acronym list.
Hs1208 👍 3 Selected: C
C. DLP (Data Loss Prevention) Data Loss Prevention (DLP) is the security measure that would most likely be configured to meet the requirements of protecting Personally Identifiable Information (PII) while using the organization's existing labeling and classification system.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Data Loss Prevention (DLP) solutions are designed to monitor, detect, and block sensitive data from leaving the corporate network. A core feature of modern DLP systems is their ability to integrate with data classification and labeling frameworks. By reading these labels, the DLP engine can apply specific policies (e.g., 'Do not allow PHI to be emailed externally') automatically, meeting the requirement to use the organization's existing system.

Why the Other Options Are Wrong

Tokenization (A) replaces sensitive data with non-sensitive equivalents but doesn't inherently use classification labels for policy enforcement across the environment. S/MIME (B) provides encryption and authentication for emails specifically, not general data protection based on labels. MFA (D) controls access to resources but does not inspect content or enforce data handling policies based on classification.

Community Comment Notes

The community consensus strongly supports C. Many users noted that "PH" is likely a typo for PHI (Protected Health Information) or PII, which are common targets for DLP. As one user paraphrased, DLP prevents data from being lost or stolen by leveraging these classifications.

Exam Strategy

When you see keywords like 'labeling', 'classification', and 'protect data' together, think DLP. Encryption and Access Control manage confidentiality and access, while DLP manages the movement and usage of classified data.

Frequently Asked Questions

Why isn't S/MIME the right choice for labeling-based protection?

S/MIME encrypts email messages specifically. It does not scan documents or other data types against classification labels across the entire network.

What does PH stand for in this context?

It is widely considered a typo for PHI (Protected Health Information) or PII (Personally Identifiable Information), both of which are standard DLP targets.

Related Analysis

← Back to SY0-601 Study Guide