nerdexam
CompTIA

CAS-001 · Question #219

A small company has a network with 37 workstations, 3 printers, a 48 port switch, an enterprise class router, and a firewall at the boundary to the ISP. The workstations have the latest patches and…

The correct answer is B. No transport security controls are implemented. The description includes strong controls for data at rest (disk encryption), strong authentication (two-factor with biometrics and passwords), and endpoint protection (patching and AV). However, there is no mention of any transport layer security such as TLS, IPsec, or VPN to…

Technical Integration of Enterprise Components

Question

A small company has a network with 37 workstations, 3 printers, a 48 port switch, an enterprise class router, and a firewall at the boundary to the ISP. The workstations have the latest patches and all have up-to-date anti-virus software. User authentication is a two-factor system with fingerprint scanners and passwords. Sensitive data on each workstation is encrypted. The network is configured to use IPv4 and is a standard Ethernet network. The network also has a captive portal based wireless hot-spot to accommodate visitors. Which of the following is a problem with the security posture of this company?

Options

  • ANo effective controls in place
  • BNo transport security controls are implemented
  • CInsufficient user authentication controls are implemented
  • DIPv6 is not incorporated in the network

How the community answered

(36 responses)
  • A
    14% (5)
  • B
    50% (18)
  • C
    8% (3)
  • D
    28% (10)

Explanation

The description includes strong controls for data at rest (disk encryption), strong authentication (two-factor with biometrics and passwords), and endpoint protection (patching and AV). However, there is no mention of any transport layer security such as TLS, IPsec, or VPN to protect data in transit across the network or over the wireless hotspot. Data transmitted between workstations, printers, or out through the firewall is unprotected in transit. Option A is wrong because several controls are present. Option C is wrong because two-factor biometric authentication is strong. Option D is wrong because IPv6 adoption is optional and not a security requirement.

Topics

#network security posture#transport security#captive portal#wireless security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice