← CCNP Security: SCOR core and operations
18 / 25 · 55 MIN

DLP and guardrails: scope and acceptance

Build a validation plan with sensitive and benign traffic, exceptions and interpretable metrics.

1. Design the coverage matrix

A fictional fund-operations team wants to use an assistant for technical summaries without sending customer data. Start with identity, destination application, traffic direction, file type and classification. For AI guardrails in Secure Access, check HTTPS inspection applying to the same identity and supported workflows. Inspection configured for another team does not establish coverage for this one. Use only synthetic data in tests: a number with a recognizable format may suffice without copying production records. The attached worksheet is a plan awaiting execution in an authorized tenant; it presents neither real Cisco-platform results nor any bank’s internal procedures.

2. Separate matching, action and outcome

A classification event says an observed match occurred. To conclude prevention, confirm applicable Block action and the submission outcome in the supported flow. Monitor enables observation without supporting the same blocking conclusion. Assigned severity helps prioritization but does not replace action. A notification also does not prove the destination never received data. During policy review, inspect rule inclusions and exclusions; an excluded identity should not be counted as protected by that same rule. This does not establish that every other policy permits it. Record each layer and avoid extrapolating a local decision to the whole service.

3. Exercise boundaries and exceptions

Plan paired tests: sensitive and benign prompt, included and excluded identity, web interface and another integration used by the business. Confirm support before assigning identical protection to an application API. If the rule targets responses only, do not count it as prompt protection. In file classification, distinguish technical label names from display text and include unlabeled documents; missing labels do not mean public information. The documented content-inspection boundary excludes text beyond the first 50 MB. A broader size filter does not establish full inspection. Keep these cases in the matrix and define alternative treatment for residual risk.

4. Interpret quality without hiding misses

The worksheet invents one hundred manually classified cases: twenty sensitive and eighty benign. The hypothetical mechanism detects eighteen sensitive cases, misses two and flags four benign ones. Recall is 18/20, or 90%; precision is 18/22, about 81.8%; false positives are 4/80, or 5% of benign cases. Accuracy is 94/100, but that number hides two possible data losses. These are not measured Cisco results. Investigate the type and severity of missed cases before accepting the change. Repeat positive and negative tests after tuning identifiers or thresholds. An exception needs rationale, scope, owner, expiry and compensating control, followed by review rather than indefinite exclusion.

5. Hand over operation and protection limits

Distinguish inline protection from SaaS API analysis of stored files. Starting a discovery scan does not mean every file was inspected; permissions, scope, queues, formats and service limits affect the outcome. At handover, provide supported-destination inventory, executed test matrix, per-class metrics, exceptions and a triage owner. A sensitive-content classifier guarantees neither truthful LLM responses nor resolution of every prompt-injection technique. For the technical summary, retain human review and restrict tools and data according to the use case. Summary: acceptance requires demonstrated coverage, observed effect and residual risk accepted by the appropriate owner.

IN PRACTICE

18 correct detections, 2 misses and 4 false alerts: recall 90%, precision 81.8%. These are fictional interpretation data, not a benchmark.

Common pitfalls

Monitor as blocking; an event as prevention; missing labels as public; isolated accuracy; started discovery as full coverage.

Related topics: SSE and HTTPS inspection · Data classification · AI risk

Take this idea with you

Accept DLP against demonstrated flow and outcome, with explicit limitations and exceptions.

Create account

Reference: Add an AI Guardrails Rule to the Data Loss Prevention Policy · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security

CCNP® and Cisco® are registered trademarks of Cisco Systems, Inc. and/or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by Cisco. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.