Content filtering, DLP, NAC, EDR/XDR and email security
This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.
This is the last of four lessons on objective 4.1. The earlier ones shaped the systems and guarded the network path. This one covers the controls that decide what leaves, who may connect, what is happening on each endpoint, and whether an email really comes from the domain it names. The email records are worth learning precisely, because the exam rewards knowing exactly which record checks what.
Why this matters
These controls answer the threats Domain 2 described. Content filtering and DLP answer data exfiltration and the careless upload. Network access control answers the unmanaged device plugged into a wall port. EDR answers fileless malware that signature antivirus cannot see. SPF, DKIM and DMARC answer the email that claims to be from your finance director.
Email authentication is three DNS records that build on each other, plus BIMI, which only works once they are enforced. Most wrong answers mix up which record does which job.
The lesson
Content filtering: DLP, agent-based filters and the central proxy
Content filtering decides what may be reached and what may leave, based on what the traffic contains or where it is going. It takes three forms.
Data loss prevention (DLP) identifies sensitive data and controls how it moves. It inspects content against patterns such as card or national identity numbers, against classification labels, and against fingerprints of known documents or database records. Where DLP sits decides which data states it sees, using the states from lesson 25:
- Endpoint DLP sees data in use: copying to USB, printing, clipboard, uploads from the device. It is the only point that sees data before it is encrypted for transit.
- Network DLP sees data in transit, but only the metadata unless TLS is inspected.
- Storage and cloud DLP sees data at rest: sensitive files in the wrong share, or a document shared with "anyone with the link".
DLP can monitor, alert, block, or quarantine and encrypt. Deploy it in monitor mode first. Untuned blocking stops legitimate work within hours and gets switched off. DLP stops carelessness and opportunism. A determined insider who retypes, photographs or encrypts data will get past it, so it sits beside access control and monitoring rather than replacing them.
Web filtering controls which destinations users may reach, usually by site category and reputation. Two delivery models suit different estates:
- A centralised proxy routes all web traffic through one point that enforces policy and logs everything. It covers only traffic that reaches it: office users, or remote users on a full-tunnel VPN.
- An agent-based filter enforces the same policy on the endpoint wherever the device is. This is what covers a laptop on hotel Wi-Fi, which is now the common case.
Most web traffic is HTTPS, so a filter sees the destination name but not the content unless it decrypts TLS, which costs certificate deployment, performance and privacy exceptions that become blind spots. Filtering by DNS name is lighter: it blocks a domain before any connection, for every application, but sees no paths or content.
Network access control: 802.1X, captive portals and the device that fails the posture check
Network access control (NAC) decides whether a device may join the network at all, and what it may reach once it does.
802.1X provides the authentication. Three roles: the supplicant is the device asking to connect; the authenticator is the switch or access point, which relays messages and opens the port only on success; the authentication server, usually RADIUS, makes the decision. The credentials travel inside EAP. EAP-TLS, with certificates on both sides, is the strongest method. Its cost is managing certificates on every device.
Posture assessment checks the device's health as well as its identity. Is it managed, patched and encrypted, and is its endpoint agent running? Policy then places it:
- a compliant corporate device goes onto the production network;
- a non-compliant one goes to a remediation network that can reach only updates and support;
- an unknown device goes to guest access or nowhere.
Agent-based posture checks see deep health but need software on the device; agentless checks cover printers, cameras and contractor laptops from the network. A re-check after admission catches a device that falls out of compliance mid-session.
A captive portal is the web page a new device is redirected to before it gets wider access. Guest Wi-Fi is the classic case: accept the terms, register, enter a sponsor's code or sign in. It is useful for accountability and for placing visitors on an isolated guest network. Know its limits. It identifies a person or an agreement, not the device's health. After login, access is often tied to the device's MAC address, which another device can copy. And an open guest network behind a portal may not encrypt traffic at all. A captive portal is right for guests. For staff devices, the answer is 802.1X with posture.
Antivirus, EDR and XDR, and what 'extended' adds
Antivirus prevents known threats on the endpoint, mainly with signatures and heuristics. It is cheap, necessary and blind to anything it has no pattern for.
Endpoint detection and response (EDR) puts an agent on the host that records behaviour: process creation and parentage, command lines, network connections, file and registry changes, script execution. It analyses that record for malicious patterns and lets responders act. They can isolate the host from everything except the management channel, kill a process, quarantine a file and collect evidence. It exists because fileless and living-off-the-land attacks use no foreign file. A signed system tool behaving strangely is invisible to a signature and obvious in a process tree.
Extended detection and response (XDR) extends the same correlation across telemetry sources: email, identity, network, cloud workloads and SaaS. One detection can then be built from a delivered phishing email, a clicked link, a spawned process and an unusual sign-in. If the exam asks what "extended" adds, that is the answer: more sources, correlated together.
Keep the neighbours apart. A SIEM aggregates and correlates logs from everything, including systems with no agent, and is the record for investigation and compliance. User behaviour analytics, often built into these tools, flags valid credentials used in an abnormal way, such as impossible travel or unusual data volume.
SPF, DKIM and DMARC, and the three records that must agree
All three are published in DNS by the domain that sends the mail, and they are checked by the server that receives it.
-
SPF (Sender Policy Framework) is a TXT record listing which servers may send mail for the domain. The receiver compares the connecting server's address with that list. Ending the record with
-allasks receivers to fail anything not listed, while~allasks only for a soft fail. SPF checks the envelope sender (the return path), not the From address the reader sees. SPF also tends to break when mail is forwarded. - DKIM (DomainKeys Identified Mail) has the sending system sign each message with a private key and publish the public key in DNS under a selector name. A valid signature proves the domain authorised the message and that the signed parts were not changed in transit. DKIM usually survives forwarding.
-
DMARC (Domain-based Message Authentication, Reporting and Conformance) is published at
_dmarcunder the domain and ties the other two together. A message passes only if SPF or DKIM passes and aligns with the domain in the visible From address. That alignment closes the gap SPF leaves. DMARC then states a policy for failures: -
p=none: take no action, just report; -
p=quarantine: treat as suspicious, usually the junk folder; -
p=reject: refuse the message.
It also asks receivers for aggregate reports (rua=), which show every system sending as your domain.
The safe deployment order, which the exam rewards: publish SPF and DKIM, set DMARC to p=none, then read the reports until every legitimate sender is accounted for. That includes the marketing platform, the ticketing system, payroll and the scanner that emails PDFs. Only then move to quarantine, and finally to reject. Going straight to reject is how an organisation stops receiving its own invoices.
None of these stops a lookalike domain with its own perfect records; gateway impersonation checks and external-sender banners cover that gap.
BIMI, and why a logo in the inbox depends on DMARC being enforced
BIMI (Brand Indicators for Message Identification) lets a domain show its logo next to its messages in mail clients that support it. It is another DNS TXT record, pointing to the logo file. Many large mailbox providers also require a mark certificate, which proves the organisation is entitled to use that logo, typically because it owns the registered trademark.
The security point is the prerequisite. A receiving provider displays the logo only if the message passes DMARC and the domain's DMARC policy is at enforcement, meaning quarantine or reject, not p=none. So a domain cannot get its logo without first doing the work that makes spoofing it hard. That is why BIMI is described as an incentive for DMARC adoption.
BIMI authenticates nothing itself: DMARC does the protecting, and BIMI displays the result. A scenario where marketing "wants the company logo shown in customers' inboxes" is really asking you to move DMARC to enforcement first.
What to take into the exam
- Endpoint DLP is the only placement that sees data in use. Deploy DLP in monitor mode first.
- A centralised proxy covers traffic that reaches it. Agent-based filtering follows the device. Neither sees inside HTTPS without decryption.
- 802.1X roles: supplicant, authenticator, authentication server. EAP-TLS is the strongest. Posture failure means the remediation network.
- Captive portals suit guests; they check acceptance, not device health.
- EDR watches behaviour and can isolate a host. XDR correlates across email, identity, network and cloud.
- SPF checks the envelope sender, DKIM signs the message, DMARC demands alignment with the visible From and sets the policy. Start at
p=noneand read the reports. - BIMI shows a logo only when DMARC is enforced (quarantine or reject). It authenticates nothing on its own.
Practise what you just read
1. Which email authentication record requires the passing domain to match the visible From address?
Select one
Show answer
C. SPF checks the envelope sender and DKIM signs the message, and either can pass for a domain the reader never sees. DMARC passes a message only if SPF or DKIM passes and aligns with the domain in the visible From address, and it states the policy for failures.
2. Marketing wants the company logo shown beside its messages in customers' inboxes. What must happen first?
Select one
Show answer
B. BIMI displays a logo only when a message passes DMARC and the domain's policy is at enforcement, meaning quarantine or reject rather than none. Many providers also require a mark certificate. BIMI authenticates nothing itself; it rewards the DMARC work that makes spoofing hard.
3. What does a captive portal on a guest wireless network actually establish before granting access?
Select one
Show answer
A. A captive portal identifies a person or an agreement, not the device's health. Access is often tied to the MAC address afterwards, which another device can copy, and the open network behind it may not encrypt traffic, so staff devices need 802.1X with posture instead.
Hands-on labs
Part of the free CompTIA Security+ SY0-801 course — 47 lessons and 78 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.