🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor43 / 148
Question 43 of 148

An IS auditor is reviewing controls at a company that recently deployed a data loss prevention (DLP) solution to prevent leakage of customer personally identifiable information (PII). During testing, the auditor discovers that a large volume of PII is being emailed externally without being blocked, even though rules exist to detect PII patterns. Investigation reveals the outbound email is encrypted by the users before sending. Which of the following is the MOST significant limitation the auditor should report?

Reviewed for accuracy · Report an issueNext question