Skip to main content

Lab 6 โ€” Preventing Data Exfiltration Using Inline Web DLP

Lab 6โฑ 25 minโš— Lab Tenant ยท Read/Write๐Ÿ‘ค Alex + Kevin
Preventing Data Exfiltration Using Inline Web DLP

In Lab 5, Alex built a custom DLP detection engine capable of identifying sensitive payroll data. Now it is time to put that engine to work. In this lab, Alex configures an Inline Web DLP policy that blocks unauthorized uploads in real time โ€” and Kevin attempts to upload the Dataparity payroll report to ChatGPT for AI analysis, only to be stopped by Inline Web DLP.

๐Ÿ”—Dependency: This lab requires the Unified DLP Engine created in Lab 5 (DP Project Code). Complete Lab 5 before proceeding.

Scenario Overviewโ€‹

This lab demonstrates the complete Inline Web DLP workflow end-to-end:

StepWhat Happens
1Alex creates a custom End User Notification (EUN)
2Alex builds an Inline Web DLP policy using the Lab 5 engine
3Kevin attempts to upload Dataparity_Q2_2025_Workforce_Financial_Summary.docx to ChatGPT
4Inline DLP inspects, detects, and blocks the upload in real time
5Kevin receives the custom EUN explaining the denial
6Alex reviews the violation in Web Insight Logs

Use the supplied payroll report to test the Lab 5 engine. DP Project Code requires all three dictionaries to match: Credit Cards AND ABA Bank Routing Number AND the custom DP Project Code dictionary, each with a count greater than zero. Payroll data or SSNs alone do not satisfy this engine.


Task 1 โ€” Admin Experience: Configure Inline DLP Protectionโ€‹

๐Ÿ›ก
Alex โ€” Security Administrator
Lab Tenant (Read/Write) โ€” Configuration Mode
You are Alex. Before a policy can block exfiltration, users need to understand why their action was denied. You will first create a custom End User Notification, then build the Inline Web DLP policy that references it.

๐ŸŽฏConfigure a custom EUN and an Inline Web DLP policy that uses the Lab 5 detection engine to block sensitive uploads.

Step 1 โ€” Navigate to End User Notification (EUN)โ€‹

Alex creates a custom End User Notification to explain why uploads containing sensitive corporate data are blocked. Clear user coaching reduces helpdesk escalations and reinforces security awareness.

Navigate to:

Policies โ†’ Common Configuration โ†’ Resources โ†’ End User Notification
Navigate to End User Notification in Common Configuration

Step 2 โ€” Add a Custom EUNโ€‹

Navigate to the Client Connector tab and click Add Custom Message. Select channel Inline Web.

Add Custom EUN for Inline Web channel

Step 3 โ€” Add the Custom Message Textโ€‹

Enter the message that will be displayed to end users when a policy violation occurs. The message should identify the policy, explain the reason for the block, and provide a contact path.

Custom EUN message text for DLP policy violation

๐Ÿ“ Suggested message: "Your file upload has been blocked because it contains sensitive Dataparity information protected under our Data Security Policy. If you believe this is an error, please contact the Security team at security@dataparity.com."

Step 4 โ€” Navigate to Inline DLP Policy Creationโ€‹

Navigate to the Inline DLP policy creation page:

Policies โ†’ Data Protection โ†’ Inline Protection โ†’ Data Loss Prevention โ†’ Add
Navigate to Inline DLP policy creation

Step 5 โ€” Configure Basic Policy Informationโ€‹

The policy window is large and split across multiple sections. The first section covers the foundational policy settings:

  • Policy Name: Block Sensitive Corporate Data Uploads
  • Rule Order: Set appropriately for your policy stack
  • User Scope: All users (or scoped to the Dataparity employee group)
  • Destination / Application Scope: Any destination for this lab (this includes sanctioned and unsanctioned destinations)
Inline DLP policy basic information โ€” name, rule order, user scope, destination scope

Step 6 โ€” Configure Policy Criteriaโ€‹

In the Criteria section, select the Unified DLP Engine created in Lab 5 โ€” DP Project Code.

This is the key connection point: the detection logic built in Lab 5 is now referenced by an enforcement policy. Lab 7 reuses this engine for Endpoint DLP; Lab 8 uses separate, preconfigured browser policies.

Policy criteria โ€” Unified DLP Engine selected from Lab 5

Step 7 โ€” Configure Policy Actionโ€‹

In the Action section:

  • Set Action = Block
  • Select the End User Notification created in Steps 1โ€“3

This completes the Detection โ†’ Enforcement โ†’ User Coaching โ†’ Logging chain.

Policy action โ€” Block with custom EUN selected
๐Ÿ’ก Key Insight

Detection โ†’ Enforcement โ†’ User Coaching โ†’ Logging. This four-step chain is the hallmark of a mature DLP deployment. Detection identifies the risk. Enforcement stops the action. User coaching reduces recurrence. Logging creates an audit trail for investigation.

Most organizations start with detection and logging only (alert mode). The shift to Block + EUN is when DLP moves from visibility to active protection.


Task 2 โ€” User Experience: Prevent Data Exfiltrationโ€‹

๐Ÿ‘ค
Kevin โ€” End User
Lab Tenant โ€” VM Session
You are Kevin. You have a Word (DOCX) copy of the Dataparity payroll report on your desktop. You will attempt to upload it to ChatGPT or one of the alternative destinations below to test the Inline Web DLP policy.

๐ŸŽฏAttempt to upload the payroll report to an unsanctioned website and observe the real-time block and user notification.

VM Required

This task must be performed from the lab VM machine. Complete Pre-Requisites for Module 2, Parts 1โ€“3: verify Inspect for the lab's HTTPS traffic in Part 2, Step 5; confirm ZCC is authenticated with its service ON and all modules active; and verify traffic steering at ip.zscaler.com.

Step 8 โ€” Attempt the Uploadโ€‹

Kevin opens a browser on the lab VM and navigates to https://chatgpt.com โ€” a GenAI platform โ€” to get an AI-powered analysis of the sensitive data.

note

No ChatGPT account? If a login is required and you cannot or prefer not to sign in, try one of these alternatives, subject to its current account and upload requirements:

Upload flows and notifications can vary by application. Verify that your chosen destination is covered by the policy and SSL inspection, then confirm the DLP block in your own Web Insights event.

He selects Dataparity_Q2_2025_Workforce_Financial_Summary.docx from the desktop and initiates an upload.

Kevin attempting to upload Dataparity_Q2_2025_Workforce_Financial_Summary.docx to ChatGPT

Expected result when the upload is inspected and matches the policy:

  1. The lab VM's upload traffic is steered through Zscaler with SSL inspection
  2. Inline DLP inspects the file content
  3. The DP Project Code engine matches all three dictionary conditions
  4. The policy blocks the upload; verify the notification and corresponding Web Insights event

Step 9 โ€” Kevin Receives the Block Notificationโ€‹

Instead of a successful upload confirmation, Kevin sees the custom End User Notification Alex configured in Task 1.

Kevin's custom End User Notification โ€” upload blocked

Task 3 โ€” Admin Experience: Review Web Insight Logโ€‹

๐Ÿ›ก
Alex โ€” Security Administrator
Lab Tenant โ€” Log Review
You are Alex. Kevin's upload attempt was blocked. Now you need to verify the event was captured, confirm the correct policy fired, and review the violation metadata โ€” the starting point for any DLP incident investigation.

๐ŸŽฏValidate that the DLP event was correctly logged in Web Insight with full metadata.

Step 10 โ€” Navigate to Web Insight Logsโ€‹

Navigate to the Web Insight log viewer:

Logs โ†’ Insights โ†’ Web Insights
Navigate to Web Insight Logs

Step 11 โ€” Apply DLP Engine Filterโ€‹

Apply a filter to isolate DLP-triggered events:

Filter: DLP Engine = DP Project Code

Web Insights โ€” filter by DLP Engine DP Project Code

Step 12 โ€” Review Violation Metadataโ€‹

Locate your upload attempt using its time, signed-in lab identity, and chosen destination. Kevin is the scenario persona; your event should show the actual test identity. Expand the matching event to review the violation record:

Web Insights โ€” DLP violation log detail with metadata

The values below are examples, not a required literal match to the screenshot. Verify your actual identity, VM/IP, chosen destination, rule, engine, file, and action. Display labels and screenshot values can vary.

FieldExample / What to Verify
User IdentityYour signed-in lab identity (playing Kevin)
Source Device / IPYour lab VM / source IP
Cloud ApplicationChatGPT, or your chosen upload application
Policy TriggeredYour rule: Block Sensitive Corporate Data Uploads
DLP Engine MatchedYour Lab 5 engine: DP Project Code
File NameYour test file: Dataparity_Q2_2025_Workforce_Financial_Summary.docx
File TypeMicrosoft Word / DOCX (display label may vary)
URL CategoryFor example, Generative AI and ML Applications for ChatGPT; verify your destination's category
Action TakenVerify Blocked for this test
Trigger Data Not Shown

This step focuses on event metadata rather than matched content. Lab 9: ZWA SOC Triage switches to the read-only Enterprise Tenant, where Priya reviews prepopulated incidents and their trigger data. Those are separate incidents, not the Lab Tenant event you generated here.

๐Ÿ’ฌ Discussion
  • The policy used Block. When would Alert-only be a better starting posture for a new DLP rule โ€” and what metrics would you use to decide when to escalate to Block?
  • Kevin uploaded to ChatGPT โ€” a GenAI tool. How would the policy behave if he attempted the same upload to a sanctioned AI platform like Microsoft Copilot?
  • The Web Insight log shows metadata but not trigger content at this stage. Why might you want to limit trigger visibility in the primary log view?
  • The Lab 5 DLP engine is shared by Labs 6 and 7. What governance process would you use to control who can modify a shared detection engine?
๐Ÿ’ก Key Insight โ€” Lab 6

GenAI uploads can expose sensitive corporate data. This lab uses the Lab 5 engine to block inspected uploads that match the configured Inline Web DLP policy. Confirm the result through the user notification and your own Web Insights event.

Lab 7 reuses the engine for Endpoint DLP Application File Access (AFA) and Clipboard controls. Lab 8 tests separate, preconfigured browser policies for copy-paste controls; it does not reuse this engine.

๐ŸŽ“
Lab Assistant
Zenith Live 2026 ยท Dataparity
Lab 6 โ€” Inline DLP
Browse all topics