QuestionQ27

Threat Hunting Outcomes

The security team at a shoe company is told by the CTO that an overseas office uses a third-party online file-transfer service. After additional investigation, the team determines that the service is shadow IT, but not malicious. The facility management team says this is the only locally government-approved method for transferring applicable tax files. The team wants to reduce possible data leakage and, if a breach occurs, limit an adversary’s ability to exfiltrate data through online services. The CTO advises the team to proceed carefully to prevent business disruption.

Which action should be taken?

Explanation

A data loss prevention (DLP) solution identifies sensitive information and applies policies to monitor or block inappropriate sharing or transfer across applications, devices, and online services. It can therefore protect sensitive tax data while allowing narrowly scoped handling for the required government-approved transfer service, avoiding the disruption of blocking all file-sharing services. Microsoft Purview DLP documentation describes DLP policies as identifying, monitoring, and automatically protecting sensitive data across enterprise applications, devices, and inline web traffic.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!