Following the implementation of a data loss prevention (DLP) tool, administrators have been overwhelmed with a high number of false positives. Which of the following is the BEST way to address this issue?
A.
Enable monitoring-only mode to permit further tuning of the solution.
B.
Educate staff about the risks of sharing sensitive information outside the organization.
C.
Amend policy rules to match approved and unapproved business information pathways.
D.
Ensure the latest signature files are present and configure regular updates.
Proper configuration and rule definition are important for DLP tools to function accurately. We recommend using monitor-only mode to minimize false positives while evaluating your actual operational situation.
A. Enable monitoring-only mode to permit further tuning of the solution.
Here’s a concise rationale for why this option is the most effective:
Enabling monitoring-only mode allows the DLP tool to continue monitoring and generating alerts without taking any enforcement actions (such as blocking or quarantining files).
This approach temporarily reduces the impact of false positives on administrators, enabling them to analyze and understand the alerts more comprehensively.
Further tuning of the DLP solution based on the data gathered during the monitoring-only period helps in identifying patterns and refining policies to reduce false positives while maintaining effective detection of actual data breaches or policy violations.
Should be C. Enabling monitoring-only mode (option A) may provide insights for further tuning, but it does not directly address the issue itself. Educating staff about risks (option B) is important for overall security awareness, but it may not immediately reduce false positives. Ensuring the latest signature files and regular updates (option D) is essential for maintaining the effectiveness of the DLP tool, but it may not directly address the issue of false positives.
from the internet: To address this issue, administrators should enable monitoring-only mode in order to fine-tune the solution. This will allow them to monitor system activity without immediately taking action on any alerts that are triggered by suspicious activity.
Why signature files need for DLP solution? I think D isn't correct answer
upvoted 3 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
saado9
Highly Voted 1 year, 6 months agoSwallows
Most Recent 4 months agoKAP2HURUF
5 months agoJONESKA
1 year, 4 months agoItsBananass
1 year, 4 months agoPakawat
1 year, 5 months agoBabaP
1 year, 6 months agokertyce
1 year, 9 months agogomboragchaa
1 year, 11 months ago