nerdexam
CompTIA

CAS-001 · Question #245

The new security policy states that only authorized software will be allowed on the corporate network and all personally owned equipment needs to be configured by the IT security staff before being…

The correct answer is C. An employee using a corporate FTP application to transfer customer lists and other proprietary. The correct answer is C. The policy addresses unauthorized software and device configuration - it does not address insider data theft using authorized tools. Loading a standard corporate image ensures employees run approved software, but it does nothing to prevent a malicious…

Enterprise Security

Question

The new security policy states that only authorized software will be allowed on the corporate network and all personally owned equipment needs to be configured by the IT security staff before being allowed on the network. The security administrator creates standard images with all the required software and proper security controls. These images are required to be loaded on all personally owned equipment prior to connecting to the corporate network. These measures ensure compliance with the new security policy. Which of the following security risks still needs to be addressed in this scenario?

Options

  • AAn employee copying gigabytes of personal video files from the employee's personal laptop to
  • BAn employee connecting their personal laptop to use a non-company endorsed accounting
  • CAn employee using a corporate FTP application to transfer customer lists and other proprietary
  • DAn employee accidentally infecting the network with a virus by connecting a USB drive to the

How the community answered

(18 responses)
  • A
    22% (4)
  • B
    11% (2)
  • C
    61% (11)
  • D
    6% (1)

Explanation

The correct answer is C. The policy addresses unauthorized software and device configuration - it does not address insider data theft using authorized tools. Loading a standard corporate image ensures employees run approved software, but it does nothing to prevent a malicious insider from using a legitimate corporate FTP application to transfer sensitive customer data (PII, proprietary information) to an external destination. This is an insider threat / data exfiltration risk that the described controls do not mitigate. Option A involves personal file copying internally. Option B is mitigated by the approved software image. Option D (USB viruses) is addressed by endpoint security controls included in the standard image.

Topics

#BYOD policy#data exfiltration#endpoint security#insider threat

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice