Protecting Sensitive Data with DLP and Classification
The Chief Information Security Officer wants to put security measures in place to protect PH. The organization needs to use its existing labeling and classification system to accomplish this goal. Which of the following would most likely be configured to meet the requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This tests knowledge of data protection mechanisms, specifically how DLP integrates with data classification to prevent unauthorized exposure or loss of sensitive information like PII/PHI.
The question asks for a security measure to protect sensitive data using existing labeling systems. Data Loss Prevention (DLP) is the correct technology as it enforces policies based on data classification labels.
Candidates often confuse DLP with encryption tools like S/MIME. While S/MIME protects data in transit via email, it does not enforce organizational labeling policies across all data types or locations.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Data Loss Prevention (DLP) solutions are designed to monitor, detect, and block sensitive data from leaving the corporate network. A core feature of modern DLP systems is their ability to integrate with data classification and labeling frameworks. By reading these labels, the DLP engine can apply specific policies (e.g., 'Do not allow PHI to be emailed externally') automatically, meeting the requirement to use the organization's existing system.Why the Other Options Are Wrong
Tokenization (A) replaces sensitive data with non-sensitive equivalents but doesn't inherently use classification labels for policy enforcement across the environment. S/MIME (B) provides encryption and authentication for emails specifically, not general data protection based on labels. MFA (D) controls access to resources but does not inspect content or enforce data handling policies based on classification.Community Comment Notes
The community consensus strongly supports C. Many users noted that "PH" is likely a typo for PHI (Protected Health Information) or PII, which are common targets for DLP. As one user paraphrased, DLP prevents data from being lost or stolen by leveraging these classifications.Exam Strategy
When you see keywords like 'labeling', 'classification', and 'protect data' together, think DLP. Encryption and Access Control manage confidentiality and access, while DLP manages the movement and usage of classified data.
Frequently Asked Questions
Why isn't S/MIME the right choice for labeling-based protection?
S/MIME encrypts email messages specifically. It does not scan documents or other data types against classification labels across the entire network.
What does PH stand for in this context?
It is widely considered a typo for PHI (Protected Health Information) or PII (Personally Identifiable Information), both of which are standard DLP targets.