nerdexam
CompTIA

CAS-001 · Question #133

Several business units have requested the ability to use collaborative web-based meeting places with third party vendors. Generally these require user registration, installation of client-based…

The correct answer is D. Evaluate several meeting providers. Evaluating several meeting providers allows the organization to identify and select a vendor that meets both the business requirement (collaboration with third parties) and security requirements (safe handling of ActiveX/Java applets, desktop sharing). A formal evaluation…

Integration of Computing, Communications and Business Disciplines

Question

Several business units have requested the ability to use collaborative web-based meeting places with third party vendors. Generally these require user registration, installation of client-based ActiveX or Java applets, and also the ability for the user to share their desktop in read-only or read- write mode. In order to ensure that information security is not compromised, which of the following controls is BEST suited to this situation?

Options

  • ADisallow the use of web-based meetings as this could lead to vulnerable client-side components
  • BHire an outside consultant firm to perform both a quantitative and a qualitative risk-based assessment.
  • CAllow the use of web-based meetings, but put controls in place to ensure that the use of these meetings
  • DEvaluate several meeting providers.

How the community answered

(55 responses)
  • A
    5% (3)
  • B
    22% (12)
  • C
    11% (6)
  • D
    62% (34)

Explanation

Evaluating several meeting providers allows the organization to identify and select a vendor that meets both the business requirement (collaboration with third parties) and security requirements (safe handling of ActiveX/Java applets, desktop sharing). A formal evaluation process compares providers on security posture, compliance certifications, data handling practices, and risk profiles before granting access. Option A is overly restrictive and ignores the legitimate business need. Option B (hiring a consultant for a full risk assessment) is disproportionate for this type of decision and doesn't directly solve the selection problem. Option C is partially correct in spirit but is less precise than a proper vendor evaluation, which is the structured approach that should precede defining controls.

Topics

#collaboration tools#vendor evaluation#third-party applications#ActiveX Java risk

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice