A security administrator is deploying a DLP solution to prevent the exfiltration of sensitive customer data. Which of the following should the administrator do first?
Choose an answer
Tap an option to check your answer.
Correct answer: Apply classifications to the data..
Why this is the answer
Applying classifications to the data is the crucial first step for a DLP solution. Without knowing what data is sensitive (e.g., PII, PCI, PHI), the DLP system cannot effectively identify, monitor, or protect it. Classifications define the sensitivity levels and types of data, allowing the DLP to apply appropriate policies. Blocking access to cloud storage or outgoing email attachments without classification is too broad and will likely disrupt legitimate business operations while still potentially missing other exfiltration vectors. Removing all user permissions is an extreme measure that would halt productivity and is not a function of DLP itself, but rather access control.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed