CAS-001 · Question #100
Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals: - Prevent data breaches from lost/stolen assets…
The correct answer is A. Implement separation of duties; enable full encryption on USB devices and cell phones, allow cell. Option A addresses the most goals from the list. Separation of duties directly reduces internal fraud by ensuring no single employee can complete a sensitive transaction alone. Full encryption on USB devices and cell phones prevents data breaches when those assets are lost or…
Question
Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals:
- Prevent data breaches from lost/stolen assets
- Reduce time to fulfill e-discovery requests
- Prevent PII from leaving the network
- Lessen the network perimeter attack surface
- Reduce internal fraud
Which of the following solutions accomplishes the MOST of these goals?
Options
- AImplement separation of duties; enable full encryption on USB devices and cell phones, allow cell
- BEliminate VPN access from remote devices. Restrict junior administrators to read-only shell access
- CCreate a change control process with stakeholder review board, implement separation of duties and
- DImplement outgoing mail sanitation and incoming SPAM filtering. Allow VPN for mobile devices;
How the community answered
(37 responses)- A70% (26)
- B8% (3)
- C5% (2)
- D16% (6)
Explanation
Option A addresses the most goals from the list. Separation of duties directly reduces internal fraud by ensuring no single employee can complete a sensitive transaction alone. Full encryption on USB devices and cell phones prevents data breaches when those assets are lost or stolen. The implied remainder of Option A (the text is truncated) likely includes DLP or email controls to prevent PII exfiltration. Option B (eliminating VPN) reduces attack surface but does not address internal fraud or PII leakage. Option C (change control with stakeholder review) is governance-focused and does not directly address encryption or PII leakage. Option D (mail sanitation and SPAM filtering) only addresses email-borne threats and PII in outgoing mail but misses physical asset encryption and fraud reduction. Option A targets the highest number of the listed goals simultaneously.
Topics
Community Discussion
No community discussion yet for this question.