Which Solution Mitigates Sensitive Data Exfiltration Risk?
An IT manager is increasing the security capabilities of an organization after a data classification initiative determined that sensitive data could be exfiltrated from the environment. Which of the following solutions would mitigate the risk?
Community Votes
67% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests precise tool-to-threat mapping, trapping candidates who conflate email authentication standards or broad detection platforms with dedicated data-leakage mitigation.
This question evaluates your ability to match a specific threat scenario—data exfiltration—with the appropriate technical control. The community overwhelmingly agrees that Data Loss Prevention (DLP) is the definitive solution for blocking unauthorized sensitive data transfers.
Candidates frequently choose DMARC or XDR, mistakenly believing that email spoofing protection or extended threat detection directly addresses internal data leakage and policy enforcement.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept
The scenario highlights a post-classification finding that sensitive information is vulnerable to exfiltration. To mitigate this risk, organizations require a control that actively monitors, classifies, and enforces policies on data both at rest and in motion.Why DLP is Correct
Data Loss Prevention (DLP) systems are explicitly engineered to identify sensitive data patterns (such as PII, financial records, or intellectual property) and block or alert on unauthorized attempts to move that data outside the corporate perimeter. As highlighted by multiple community members, DLP solutions monitor real-time traffic, detect suspicious activity, and can automatically quarantine transfers, making them the industry standard for this exact use case. The consensus strongly reinforces that DLP is purpose-built for preventing data leakage after classification initiatives identify high-risk assets.Why Other Options Fail
- XDR (Extended Detection and Response) focuses on correlating telemetry across endpoints, networks, and clouds to detect advanced threats and malware, not specifically on enforcing data-handling policies or content inspection.
- SPF (Sender Policy Framework) and DMARC (Domain-based Message Authentication, Reporting, and Conformance) are email authentication protocols designed to prevent domain spoofing and phishing attacks. They validate sender identity but have zero capability to inspect or stop file transfers containing sensitive organizational data.
Exam Context
CompTIA Security+ heavily emphasizes matching security objectives to control types. Remember that any question referencing 'classification,' 'leakage,' or 'unauthorized transfer' points directly to data-centric controls like DLP, encryption, or tokenization rather than perimeter, network, or identity solutions.Official Reference
- NIST Special Publication 800-101 Rev. 1: Guidelines on Data Loss Prevention
- CompTIA Security+ SY0-701 Objective 4.5: Compare and contrast security products and technologies
- RFC 7208: Sender Policy Framework (SPF)
- RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
Exam Strategy
Always anchor your answer to the primary function of each technology rather than its general security benefits. When you see keywords like 'data classification' or 'exfiltration,' immediately filter out email and endpoint detection options to isolate data-centric controls like DLP.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →