ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
An organization stores customer data inside a cloud-based CRM accessed through corporate laptops. Security leadership wants to stop employees from saving exported customer lists onto personal USB flash drives, while allowing them to continue to view the data in the web portal. Which Data Loss Prevention (DLP) capability most directly addresses this requirement?
Enable storage-based DLP scanning within the SaaS CRM to tag sensitive records at rest.
Apply tokenization to customer fields before they are stored in the CRM database.
Deploy an endpoint-based DLP agent that enforces policies blocking or encrypting writes to removable media.
Implement a network DLP solution on the Internet firewall to inspect outbound SMTP and web traffic for customer data.
Preventing users from copying sensitive data to removable media is an endpoint problem, because the data have already reached the user's workstation via the browser. An endpoint-based DLP agent can inspect content as it leaves the protected host and enforce policies that block or encrypt writes to USB storage. Network DLP focused on e-mail or other egress channels would miss a local save-to-USB action that never traverses the network. Storage-based DLP in the SaaS repository can label or encrypt data at rest but cannot control what users do after legitimate download. Tokenizing data in the CRM would require application changes and, once detokenized on the endpoint, would not by itself prevent copying to external media. Therefore, deploying endpoint DLP with removable-media control is the most effective choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an endpoint-based DLP agent?
Open an interactive chat with Bash
How does endpoint DLP differ from network and storage DLP solutions?
Open an interactive chat with Bash
Why is tokenization insufficient to prevent copying to external devices?
Open an interactive chat with Bash
How do endpoint-based DLP agents block or encrypt writes to USB storage?
Open an interactive chat with Bash
Why wouldn't a network DLP solution catch local save-to-USB actions?
Open an interactive chat with Bash
What are the benefits of tokenization and why doesn't it address this requirement?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .