In a Network Prevent content response rule, which action is appropriate when the content cannot be removed?

Prepare for the Symantec Data Loss Prevention (DLP) Exam with targeted quizzes and detailed explanations. Boost your knowledge and confidence with our engaging study tools!

Multiple Choice

In a Network Prevent content response rule, which action is appropriate when the content cannot be removed?

Explanation:
When content is detected by a Network Prevent content response rule and you can’t remove it from the message, blocking the content before posting is the appropriate action. This enforces the policy at the network edge, stopping the sensitive data from leaving the organization. If you allowed the content to be posted, the data would escape; removing the rule would disable enforcement entirely; and merely notifying an administrator doesn’t prevent the transmission in real time. Blocking provides immediate protection for data in motion.

When content is detected by a Network Prevent content response rule and you can’t remove it from the message, blocking the content before posting is the appropriate action. This enforces the policy at the network edge, stopping the sensitive data from leaving the organization. If you allowed the content to be posted, the data would escape; removing the rule would disable enforcement entirely; and merely notifying an administrator doesn’t prevent the transmission in real time. Blocking provides immediate protection for data in motion.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy