Knowledge Check
You have completed all 9 labs across three modules. Use these questions to connect the complementary Dataparity exercises while distinguishing observed evidence, student-built controls, and preconfigured examples.
Module 1 โ Visibilityโ
Q1. In Labs 1โ4, Alex observed Dataparity's environment without enforcing any blocking policies. Why is it important to start with visibility before enforcement โ and what risk does skipping this step create?
Q2. In Lab 3, how did Endpoint Data Scan, User Investigation's Data at Rest and Timeline views, Application Investigation, and connected-device Inventory contribute different parts of the endpoint picture? Use one example of a classification, incident, application, and device association. Why is the ZIA-calculated User Risk Profile not simply the sensitive-file count, and why does a device Allow record not prove that sensitive data was successfully exfiltrated?
Q3. Instance Discovery in Lab 1 distinguishes between corporate and personal instances of the same application (e.g., corporate Google Drive vs. personal Google Drive). Why does this matter for a DLP policy โ and what would happen if you blocked the application rather than the personal instance?
Module 2 โ Protectionโ
Q4. Lab 5's DP Project Code engine combines Credit Cards AND ABA Bank Routing Number AND the custom DP Project Code dictionary, each with a condition greater than zero. Labs 6 and 7 reuse this engine; Lab 8 uses separate preconfigured browser policies. What benefit does detection reuse provide, and why do channel-specific policies and tests still matter?
Q5. Compare the six protection activities in Module 2. Complete the table with the control and outcome you observed; do not treat masking or watermarking as a block.
| Activity | Lab | Control / enforcement point | Observed outcome | Evidence or notification |
|---|---|---|---|---|
| Upload workforce financial summary to ChatGPT or a listed alternative | Lab 6 | |||
| Open the same document directly in Notepad++ | Lab 7 | |||
| Open in Word, copy content, and paste into Notepad++ | Lab 7 | |||
| Paste supplied customer text into a ChatGPT prompt | Lab 8 | |||
| Download the Name + SSN + CCN sample as PDF from dlptest.com/sample-data/ | Lab 8 | |||
| View the designated document in Chrome | Lab 8 |
Q6. Lab 6 reviews Web Insights, and Lab 7 reviews Endpoint DLP Insights. Lab 9 explores an independent pre-populated Workflow Automation queue with Inline and Endpoint filters. How does a combined incident view support triage, and what evidence would you need before linking a queue record to one of your own Lab Tenant tests?
Q7. Lab 8 tests Chrome with an authenticated Browser DLP extension. What deployment and policy checks would you make before claiming equivalent coverage in another browser? Which activities from Labs 6 and 7 could other layers address, and why should you not assume they reproduce browser masking or watermarking?
Q8. Lab 7's Clipboard rule was scoped to Notepad++ (Windows) as the destination application. A colleague suggests changing the destination to Any to maximize protection. What is the trade-off of setting destination to Any โ and under what circumstances would you keep it scoped to a specific application?
Module 3 โ Investigationโ
Q9. In Lab 9, the User Notifications table records an email to the originating user, and State Changes attributes Notify User and Change Status entries to a named admin. What do the channel, status, timestamp, and Changed By fields actually establish? What additional evidence would be needed to attribute the notification to a particular workflow, rather than inferring it from the incident status or the template you previewed?
Q10. Priya filtered the pre-populated queue by Source DLP Type = Inline + Endpoint. What would adding SaaS Security let her explore if matching records exist? Why would reviewing dashboards in the read-only Module 1 labs not itself generate those SaaS incidents?
Cross-Lab Synthesisโ
Q11. Dataparity and the three personas connect the workshop, but the labs do not trace one file across all three modules.
- How do Alex's visibility and policy work, Kevin's protection tests, and Priya's read-only investigation complement each other?
- Which document is actually reused in Labs 6 and 7, and how do Lab 8's customer text, sample PDF download, and watermarked document differ?
- Why should the independent records in Labs 3, 4, and 9 not be treated as the same file or the student's incident? Consider Lab 9's attachment/post, dlptest.com, and CC SSN HIPAA Block fields.
Q12. A customer asks: "If I deploy Inline Web DLP, Endpoint DLP, and Browser DLP, am I fully protected?" Based on Labs 6โ8, what would you say? Consider SSL inspection, agent and extension deployment, rule scope, untested channels, and the difference between a preventive block and a deterrent watermark.