Cybersecurity lab · DLP test bench
DLP rule test matrix
One page per rule from the POV guide. Every page states the rule it exercises,
the exact steps to execute, and the verdict Chrome Enterprise Premium should return.
Replace the guide's example URL conditions (news.google.com, cnn.com,
dlptest.com) with this server's hostname — cepdemo.mobi-sec.de —
so the rules fire against these pages. All PII/PCI payloads come from the
sample data library, generated to the dlptest.com dataset schemas.
| # | Rule under test | Trigger on this site | Expected verdict |
|---|---|---|---|
| 1 | URL filtering | Navigate to a Generative-AI URL | Block |
| 2 | Watermarking | Open the watermark target page | Audit + watermark |
| 3 | Screenshot & screen-share prevention | Screenshot / share the protected page | Audit + obscure |
| 4 | URL audit | Navigate to any non-internal URL | Audit only |
| 5 | PII DLP (credit cards) | Upload / download / paste / print CC data | Block |
| 6 | Paste source control | Paste from incognito, other profile, other app | Block |
| 7 | Data masking (SSN, hover) | View a page containing SSNs | Mask |
| 8 | Unmanaged profile · block downloads | Download any file from an unmanaged profile | Block |
| 9 | Copy/paste policy (optional) | Copy from here into incognito / other apps | Block |
Before you start: the connectors
(Upload, Download, Bulk text, Print content analysis) must be set to Chrome Enterprise
Premium with the advanced settings from the guide, and the test browser must be signed in
to a managed profile in scope of the Users OU. Rules scoped to URL conditions must be
updated to match this host.