SY0-701 exam dumps

SY0-701 practice question 335 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 335

Single answerDLP

A healthcare organization allows employees to use a cloud-based email service and web browser access from managed laptops. During an internal audit, the security team discovers several incidents in which staff emailed spreadsheets containing patient records to personal email accounts so they could work from home. Management wants to reduce the risk of regulated data leaving the company while still allowing legitimate business use of email. Which control would BEST address this requirement?

  1. A

    Implement a DLP solution that inspects outbound email and web uploads for PHI patterns and blocks or quarantines policy violations

  2. B

    Require all employees to use full-disk encryption on their laptops so patient data cannot be read if a device is stolen

  3. C

    Deploy network segmentation between user workstations and the electronic medical record servers

  4. D

    Enable multifactor authentication for the cloud email platform to prevent unauthorized logins

Show answer and explanation

Correct answer: A

Explanation

The best answer is the DLP control because the scenario is specifically about preventing sensitive data exfiltration through outbound email and browser-based channels by authorized users. In Security+ terms, DLP is intended to detect and prevent unauthorized transmission of sensitive information based on content, context, and policy. In healthcare environments, PHI handling is especially important due to regulatory obligations under HIPAA. Industry best practices and major vendor documentation consistently describe DLP capabilities such as inspecting email, attachments, and web uploads; applying policies based on data identifiers; and taking actions like blocking, quarantining, or generating alerts. The other controls are valuable security measures, but they address different risks: encryption protects data at rest, segmentation limits network exposure, and MFA strengthens authentication. None of them directly provides the content-aware outbound protection required in this scenario.

  • A. Correct.

    Correct. A data loss prevention (DLP) solution is designed to identify sensitive data such as protected health information (PHI) using content inspection, pattern matching, dictionaries, labels, and policy rules. In this scenario, the issue is authorized users attempting to send sensitive data out through email or web channels. Email and web DLP can detect those outbound transfers and block, quarantine, encrypt, or alert based on policy. This directly addresses the stated goal of preventing regulated data from leaving the organization while preserving legitimate business email use.

  • B. Incorrect.

    Incorrect. Full-disk encryption protects data at rest on the laptop if the device is lost or stolen, but it does not prevent a user from intentionally or accidentally emailing spreadsheets with PHI to a personal account. This is a common confusion between protecting stored data and controlling data exfiltration channels.

  • C. Incorrect.

    Incorrect. Network segmentation can reduce lateral movement and limit access between systems, but it does not specifically inspect outbound email messages or browser uploads for sensitive content. It may improve overall security architecture, but it does not best solve the problem of users sending regulated data outside the organization through approved communication channels.

  • D. Incorrect.

    Incorrect. Multifactor authentication helps ensure that only authorized users access the email platform, reducing account compromise risk. However, the scenario involves legitimate users misusing their access by sending PHI externally. MFA does not provide content-aware controls over what data can be transmitted.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam