ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your organization processes card data and runs an inline network DLP appliance at the internet edge. Employee web traffic already goes through an explicit forward proxy that can perform SSL/TLS interception. After deployment, the DLP shows no credit-card matches when you upload test data via an HTTPS form. Without installing endpoint agents, which change will best let the DLP detect cardholder data in transit?
Update the DLP appliance's pattern-matching signatures for credit-card numbers and increase scan sensitivity.
Enable NetFlow export on the edge router and forward flow logs to the DLP device for analysis.
Configure the proxy to terminate outbound TLS connections and re-sign traffic with an internal certificate authority so the DLP appliance receives decrypted content.
Add a URL-filtering subscription to the proxy and block destinations classified as High-Risk.
A network-based DLP appliance can only analyze content it can read. Because the card data travels inside an HTTPS session, the payload remains encrypted when it reaches the DLP sensor. Terminating TLS on the forward proxy, decrypting the traffic, and then re-encrypting it with certificates from an internal CA exposes clear-text HTTP to the DLP for inspection. Updating signatures, adding URL filtering, or analyzing NetFlow do not decrypt traffic, so sensitive data inside TLS remains invisible.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SSL/TLS interception and why is it important for DLP functionality?
Open an interactive chat with Bash
How does a forward proxy help with TLS interception and DLP inspection?
Open an interactive chat with Bash
Why can’t NetFlow and URL filtering detect sensitive data in encrypted outbound HTTPS traffic?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .