exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 162 discussion

Actual exam question from CompTIA's SY0-601
Question #: 162
Topic #: 1
[All SY0-601 Questions]

The Chief Information Security Officer is concerned about employees using personal email rather than company email to communicate with clients and sending sensitive business information and PII. Which of the following would be the BEST solution to install on the employees' workstations to prevent information from leaving the company's network?

  • A. HIPS
  • B. DLP
  • C. HIDS
  • D. EDR
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tibetbey
Highly Voted 2 years, 8 months ago
Selected Answer: B
DLP enables businesses to detect data loss, as well as prevent the illicit transfer of data outside the organization and the unwanted destruction of sensitive or personally identifiable data (PII).
upvoted 19 times
...
Joe1984
Highly Voted 2 years, 9 months ago
Shouldn't this be DLP? (Data Loss Prevention)
upvoted 12 times
enginne
2 years, 9 months ago
DLP is good answer
upvoted 6 times
...
...
BD69
Most Recent 1 year, 2 months ago
Selected Answer: B
Suggested answer, EDR, doesn't really fit the question and has limited effectiveness. EDR software is designed to look for attacks and suspicious activity, but would have no way if information that is emailed outbound is corporately protected or not. DLP systems will look at information to determine if it's corporate or not.
upvoted 1 times
...
RevolutionaryAct
1 year, 9 months ago
Selected Answer: B
Zero question that it is DLP, this goes into some detail about the differences https://www.xcitium.com/what-is-the-difference-between-edr-and-dlp
upvoted 3 times
...
sujon_london
1 year, 9 months ago
Selected Answer: B
While EDR software provides advanced threat detection, investigation, and response capabilities, it does not prevent information from leaving the company's network by monitoring data movement and controlling exit points. Therefore, DLP software is the best solution to prevent information from leaving the company's network when employees use personal email to communicate with clients and send sensitive business information and PII
upvoted 1 times
...
Dan_26
2 years ago
DLP is Prevention. Stopping things before they happen. EDR is Endpoint Detection and Response - closing the gate after the horse has bolted.
upvoted 3 times
...
Kaps443
2 years, 1 month ago
Selected Answer: B
The BEST solution to prevent information from leaving the company's network in this scenario would be DLP (Data Loss Prevention). DLP solutions are designed to detect and prevent the unauthorized transmission of sensitive data outside of the network. It can monitor email messages, file transfers, and other communications, and can be configured to block or quarantine any outbound traffic that contains sensitive information. HIPS (Host Intrusion Prevention System), HIDS (Host-based Intrusion Detection System), and EDR (Endpoint Detection and Response) are security solutions that are primarily focused on detecting and responding to various forms of malicious activity on a system or network. While they may be helpful in detecting unauthorized data exfiltration, they are not specifically designed for this purpose like DLP.
upvoted 1 times
...
Yawannawanka
2 years, 1 month ago
The BEST solution to prevent sensitive business information and PII from leaving the company's network via personal email would be to install a Data Loss Prevention (DLP) solution on the employees' workstations. DLP solutions can detect and prevent the transmission of sensitive data, including confidential business information and personally identifiable information (PII), outside of the company's network. DLP solutions can also provide policy-based enforcement to prevent employees from sending such data via personal email, and can alert security teams when such attempts occur. While Host-based Intrusion Prevention Systems (HIPS), Host-based Intrusion Detection Systems (HIDS), and Endpoint Detection and Response (EDR) solutions can provide protection against other types of threats, such as malware and unauthorized access attempts, they are not specifically designed to prevent data loss through personal email. Therefore, the best solution in this scenario would be to install a DLP solution on the employees' workstations to prevent sensitive information from being sent outside the company's network via personal email.
upvoted 1 times
...
TheGuitarMan_61
2 years, 1 month ago
B) The greatest drawback of EDR is that it is a reactive approach. Traditional EDR tools rely on behavioral analysis which means the threat has executed on the endpoint and it's a race against time to stop it before any damage is done.
upvoted 1 times
...
carpathia
2 years, 6 months ago
Selected Answer: B
EDR includes DLP, but it (EDR) would not be necessary here, a bit of an overkill. DLP is OK.
upvoted 1 times
BD69
1 year, 2 months ago
Since when? EDR is geared towards malware, not data. If there are solutions with EDR that includes DLP, I'd love to see them.
upvoted 1 times
...
...
Sir_Learnalot
2 years, 6 months ago
I´ll go with DLP on this one. EDR is a software agent that collects system data and logs for analysis by a monitoring system to provide early detection of threats. It´s not so much on preventing bad things. The Problem is there a dozent of different solutions out there with different acronyms. I guess a EPP (Enpoint Protection Platform) could be mistaken with EDR here. EPP solutions will act on these things as they often include DLP, HIDS/HIPS, firewall and AV in one package...but guess this also depends on the definition. Long story short, I think it´s "B" DLP in this case
upvoted 1 times
...
zharis
2 years, 7 months ago
Selected Answer: B
DLP is software solution that detects and prevents sensitive information from being stored on unauthorized systems or transmitted over unauthorized networks
upvoted 3 times
...
CertAddict69
2 years, 8 months ago
Selected Answer: B
The answer is B. D would be over thinking it.
upvoted 3 times
...
KetReeb
2 years, 9 months ago
Selected Answer: D
I believe D is correct since EDR includes some DLP for endpoints: Endpoint detection and response (EDR) solutions are integrated solutions that combine individual endpoint security functions into a complete package. Having a packaged solution makes updating easier, and frequently these products are designed to integrate into an enterprise-level solution with a centralized management platform. Some of the common EDR components include antivirus, anti-malware, software patching, firewall, and DLP solutions. Unified endpoint management (UEM) is a newer security model that focuses on the managing and securing devices in an enterprise such as desktops, laptops, smartphones, and other devices from a single location.
upvoted 7 times
stoneface
2 years, 9 months ago
If they are asking for only one thing, why would we give them more?
upvoted 4 times
...
anonimouse2
2 years, 9 months ago
That may be true, but the trend with these types of questions is that PII/business information + not allowed to leave company network = DLP everytime
upvoted 2 times
...
RonWonkers
2 years, 8 months ago
Information not being allowed to leave the company network == DLP any time
upvoted 2 times
...
deeden
2 years, 8 months ago
I'm a bit confused by how the question is worded. The CISO's concern is clearly the use of personal emails. So, what if employees send sensitive info via corporate email it's okay? Or maybe, the corporate email security is hardened and has DLP already and that they can't implement DLP on personal emails e.g. yahoo mail? Then the solution must be to block the use of personal emails in any end point corporate devices, which could be a reverse-proxy solution, or MDM solution for mobile devices, I think. Not sure if EDR is capable of both?
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...