nerdexam
CompTIA

CAS-001 · Question #100

Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals: - Prevent data breaches from lost/stolen assets…

The correct answer is A. Implement separation of duties; enable full encryption on USB devices and cell phones, allow cell. Option A addresses the most goals from the list. Separation of duties directly reduces internal fraud by ensuring no single employee can complete a sensitive transaction alone. Full encryption on USB devices and cell phones prevents data breaches when those assets are lost or…

Integration of Computing, Communications and Business Disciplines

Question

Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals:

  • Prevent data breaches from lost/stolen assets
  • Reduce time to fulfill e-discovery requests
  • Prevent PII from leaving the network
  • Lessen the network perimeter attack surface
  • Reduce internal fraud

Which of the following solutions accomplishes the MOST of these goals?

Options

  • AImplement separation of duties; enable full encryption on USB devices and cell phones, allow cell
  • BEliminate VPN access from remote devices. Restrict junior administrators to read-only shell access
  • CCreate a change control process with stakeholder review board, implement separation of duties and
  • DImplement outgoing mail sanitation and incoming SPAM filtering. Allow VPN for mobile devices;

How the community answered

(37 responses)
  • A
    70% (26)
  • B
    8% (3)
  • C
    5% (2)
  • D
    16% (6)

Explanation

Option A addresses the most goals from the list. Separation of duties directly reduces internal fraud by ensuring no single employee can complete a sensitive transaction alone. Full encryption on USB devices and cell phones prevents data breaches when those assets are lost or stolen. The implied remainder of Option A (the text is truncated) likely includes DLP or email controls to prevent PII exfiltration. Option B (eliminating VPN) reduces attack surface but does not address internal fraud or PII leakage. Option C (change control with stakeholder review) is governance-focused and does not directly address encryption or PII leakage. Option D (mail sanitation and SPAM filtering) only addresses email-borne threats and PII in outgoing mail but misses physical asset encryption and fraud reduction. Option A targets the highest number of the listed goals simultaneously.

Topics

#data loss prevention#e-discovery#PII protection#risk reduction strategy

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice