An organization needs to prevent employees from emailing documents containing credit card numbers to external recipients. However, the policy must allow for legitimate business cases where a user can send the information after providing a reason. Which combination of actions should an administrator configure in the Data Loss Prevention (DLP) policy rule?
-
A
Set the action to 'Restrict access' and enable 'User notifications'.
-
B
Set the action to 'Audit only' and configure an 'Incident report'.
-
C
Set the action to 'Restrict access' to block external users, and enable 'User overrides' with a business justification.
-
D
Set an 'Exception' for the finance department and set the action to 'Encrypt the message content'.