
EC-CouncilNetwork Defense Essentials
Domain 6Objective 5
Data Loss Prevention (DLP) Concepts NDE Practice Questions (Page 5)
Part of the Cryptography, PKI, and Data Security domain, which makes up ~15% of our current practice bank.
49questions here
10free pages
8concepts
Questions 21–25
- 21
A DLP administrator configures a policy that blocks outbound emails containing credit card numbers. During a pilot, a finance user's legitimate invoice email is blocked because a customer's reference number looks like a card number. What is the most appropriate immediate remediation step?
Select an answer first - 22
A DLP alert fires when a user attempts to copy a customer database to a USB drive. The policy is set to 'block with notification'. The user claims the file was needed for a legitimate offline analysis. What is the most appropriate next step in the incident response workflow?
Select an answer first - 23
A DLP administrator is creating a policy to protect sensitive documents that are stored in a shared network drive. The documents are not consistently labeled, and the administrator wants to detect them based on their content. The policy must minimize false positives. Which detection method should be used?
Select an answer first - 24
Which DLP deployment mode is most appropriate for protecting data stored in cloud applications like Office 365 or Google Drive?
Select an answer first - 25
What is the typical first action in a DLP incident response workflow when a policy violation is detected?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.