exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 442 discussion

Actual exam question from Isaca's CISA
Question #: 442
Topic #: 1
[All CISA Questions]

Which of the following is the BEST control to help prevent sensitive data leaving an organization via email?

  • A. Scanning outgoing emails
  • B. Blocking outbound emails sent without encryption
  • C. Conducting periodic phishing tests
  • D. Providing encryption solutions for employees
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Greens
3 weeks, 5 days ago
Selected Answer: B
The best control to prevent sensitive data from leaving an organization via email is to block outbound emails that are not encrypted. Why? Sensitive data should never leave the organization unprotected. Blocking unencrypted outbound emails enforces compliance and prevents human error or intentional data leaks. It acts as a proactive, automated control, rather than a reactive or user-dependent one. Why not the others? A. Scanning outgoing emails This is a detective control and may identify issues after the fact, but it does not prevent data from being sent. C. Conducting periodic phishing tests Helpful for training and awareness, but it addresses a different threat (social engineering), not data leakage prevention. D. Providing encryption solutions for employees While valuable, simply providing tools doesn’t guarantee their use—it lacks enforcement. Employees may forget or misuse them.
upvoted 1 times
...
roxannebadenhorst
6 months, 2 weeks ago
Selected Answer: B
blocking outbound emails sent without encryption aligns with ISACA CISA standards for information security and data protection. According to the CISA (Certified Information Systems Auditor) guidelines, preventive controls (such as blocking unencrypted emails containing sensitive information) are critical for protecting sensitive data and ensuring compliance with data privacy and confidentiality requirements. The idea is to proactively prevent unauthorized or insecure transmission of sensitive information.
upvoted 1 times
...
Swallows
7 months ago
Selected Answer: D
While scanning outgoing emails (option A) can be a valuable control for detecting certain types of sensitive information in emails, it may not be foolproof and can sometimes generate false positives or miss certain types of sensitive data. Therefore, providing encryption solutions for employees is generally considered the most effective control for preventing sensitive data from leaving an organization via email.
upvoted 2 times
...
KAP2HURUF
10 months, 1 week ago
Selected Answer: A
A. Scanning outgoing emails: This control allows for proactive detection of sensitive data within outgoing email messages. By implementing a data loss prevention (DLP) solution that scans outgoing email content, the organization can identify and potentially block emails containing sensitive information, preventing unauthorized data exfiltration.
upvoted 1 times
...
oldmagic
1 year, 6 months ago
Selected Answer: A
A is correct. Enforcing encryption for outgoing email does not help with preventing users from sharing sensitive information
upvoted 3 times
...
hoho
1 year, 7 months ago
On B, Block outbound, only allow encryption
upvoted 2 times
...
zebree
1 year, 11 months ago
Selected Answer: B
The BEST control to help prevent sensitive data leaving an organization via email is 'Blocking outbound emails sent without encryption.' This control ensures that all sensitive information is protected by encryption and reduces the risk of sensitive data being intercepted or intercepted by unauthorized individuals.
upvoted 1 times
...
Tsubasa1234
2 years ago
Selected Answer: A
I think A is right. Scanning is work as DLP.
upvoted 2 times
...
David_Hu
2 years ago
Selected Answer: B
should be B
upvoted 1 times
MOHAMMADSALTI
1 year, 12 months ago
But the data will be leaked
upvoted 2 times
...
...
Staanlee
2 years, 1 month ago
Selected Answer: B
D. Blocking outbound emails sent without encryption is the right answer.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...