Which Solution Mitigates Sensitive Data Exfiltration Risk?

An IT manager is increasing the security capabilities of an organization after a data classification initiative determined that sensitive data could be exfiltrated from the environment. Which of the following solutions would mitigate the risk?

  1. XDR
  2. SPF
  3. DLP Source Reference Answer
  4. DMARC

Community Votes

C
67%
D
33%

67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests precise tool-to-threat mapping, trapping candidates who conflate email authentication standards or broad detection platforms with dedicated data-leakage mitigation.

This question evaluates your ability to match a specific threat scenario—data exfiltration—with the appropriate technical control. The community overwhelmingly agrees that Data Loss Prevention (DLP) is the definitive solution for blocking unauthorized sensitive data transfers.

Candidates frequently choose DMARC or XDR, mistakenly believing that email spoofing protection or extended threat detection directly addresses internal data leakage and policy enforcement.

Community Discussion (7 comments)

March2023 👍 1 Selected: C
C for sure
Syl0 👍 1
XDR - Extended Detection and Response SPF - Sender Policy Framework - for Email to identify who can send to the domain DLP - Data Loss Prevention DMARC - similar as SPF, helps with email
Glacier88 👍 1 Selected: C
DLP solutions are specifically designed to identify and prevent the unauthorized movement of sensitive data within and outside an organization. They can monitor data in real-time, detect suspicious activity, and take actions like blocking data transfers or alerting administrators.
Ina22 👍 2
DLP is the unswer
Justhereforcomptia 👍 1 Selected: C
DLP is the right option, it stops data from being exfiltrated from your environment.
TheDorse 👍 1 Selected: C
DLP solutions are specifically designed to monitor, detect, and prevent unauthorized data transfers or leaks outside the organization. DLP can identify sensitive data and enforce policies to prevent it from being exfiltrated, making it the most effective solution for mitigating the risk of data exfiltration.
RoRoRoYourBoat 👍 2 Selected: D
Answer D: EDR is used designed to detect, investigate, and respond to advanced threats to prevent them from spreading across the network.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept

The scenario highlights a post-classification finding that sensitive information is vulnerable to exfiltration. To mitigate this risk, organizations require a control that actively monitors, classifies, and enforces policies on data both at rest and in motion.

Why DLP is Correct

Data Loss Prevention (DLP) systems are explicitly engineered to identify sensitive data patterns (such as PII, financial records, or intellectual property) and block or alert on unauthorized attempts to move that data outside the corporate perimeter. As highlighted by multiple community members, DLP solutions monitor real-time traffic, detect suspicious activity, and can automatically quarantine transfers, making them the industry standard for this exact use case. The consensus strongly reinforces that DLP is purpose-built for preventing data leakage after classification initiatives identify high-risk assets.

Why Other Options Fail

  • XDR (Extended Detection and Response) focuses on correlating telemetry across endpoints, networks, and clouds to detect advanced threats and malware, not specifically on enforcing data-handling policies or content inspection.
  • SPF (Sender Policy Framework) and DMARC (Domain-based Message Authentication, Reporting, and Conformance) are email authentication protocols designed to prevent domain spoofing and phishing attacks. They validate sender identity but have zero capability to inspect or stop file transfers containing sensitive organizational data.

Exam Context

CompTIA Security+ heavily emphasizes matching security objectives to control types. Remember that any question referencing 'classification,' 'leakage,' or 'unauthorized transfer' points directly to data-centric controls like DLP, encryption, or tokenization rather than perimeter, network, or identity solutions.

Official Reference

  • NIST Special Publication 800-101 Rev. 1: Guidelines on Data Loss Prevention
  • CompTIA Security+ SY0-701 Objective 4.5: Compare and contrast security products and technologies
  • RFC 7208: Sender Policy Framework (SPF)
  • RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)

Exam Strategy

Always anchor your answer to the primary function of each technology rather than its general security benefits. When you see keywords like 'data classification' or 'exfiltration,' immediately filter out email and endpoint detection options to isolate data-centric controls like DLP.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide