CAS-001 · Question #219
A small company has a network with 37 workstations, 3 printers, a 48 port switch, an enterprise class router, and a firewall at the boundary to the ISP. The workstations have the latest patches and…
The correct answer is B. No transport security controls are implemented. The description includes strong controls for data at rest (disk encryption), strong authentication (two-factor with biometrics and passwords), and endpoint protection (patching and AV). However, there is no mention of any transport layer security such as TLS, IPsec, or VPN to…
Question
A small company has a network with 37 workstations, 3 printers, a 48 port switch, an enterprise class router, and a firewall at the boundary to the ISP. The workstations have the latest patches and all have up-to-date anti-virus software. User authentication is a two-factor system with fingerprint scanners and passwords. Sensitive data on each workstation is encrypted. The network is configured to use IPv4 and is a standard Ethernet network. The network also has a captive portal based wireless hot-spot to accommodate visitors. Which of the following is a problem with the security posture of this company?
Options
- ANo effective controls in place
- BNo transport security controls are implemented
- CInsufficient user authentication controls are implemented
- DIPv6 is not incorporated in the network
How the community answered
(36 responses)- A14% (5)
- B50% (18)
- C8% (3)
- D28% (10)
Explanation
The description includes strong controls for data at rest (disk encryption), strong authentication (two-factor with biometrics and passwords), and endpoint protection (patching and AV). However, there is no mention of any transport layer security such as TLS, IPsec, or VPN to protect data in transit across the network or over the wireless hotspot. Data transmitted between workstations, printers, or out through the firewall is unprotected in transit. Option A is wrong because several controls are present. Option C is wrong because two-factor biometric authentication is strong. Option D is wrong because IPv6 adoption is optional and not a security requirement.
Topics
Community Discussion
No community discussion yet for this question.