nerdexam
CompTIA

CAS-001 · Question #263

Employees have recently requested remote access to corporate email and shared drives. Remote access has never been offered; however, the need to improve productivity and rapidly responding to…

The correct answer is C. Plan and develop security policies based on the assumption that external environments have. When designing remote access security, the most robust architectural principle is to assume that external environments (home networks, coffee shops, hotel Wi-Fi) are hostile and untrusted. This 'zero-trust' or 'hostile external environment' assumption drives the strongest…

Enterprise Security

Question

Employees have recently requested remote access to corporate email and shared drives. Remote access has never been offered; however, the need to improve productivity and rapidly responding to customer demands means staff now requires remote access. Which of the following controls will BEST protect the corporate network?

Options

  • ADevelop a security policy that defines remote access requirements.
  • BSecure remote access systems to ensure shared drives are read only and access is provided
  • CPlan and develop security policies based on the assumption that external environments have
  • DImplement a DLP program to log data accessed by users connecting via remote access.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    76% (19)
  • D
    16% (4)

Explanation

When designing remote access security, the most robust architectural principle is to assume that external environments (home networks, coffee shops, hotel Wi-Fi) are hostile and untrusted. This 'zero-trust' or 'hostile external environment' assumption drives the strongest security controls - encrypting all traffic, requiring strong authentication (MFA), using VPN tunnels, and validating devices before granting access. Developing a policy (A) is important but a policy alone doesn't protect the network. Making shared drives read-only (B) is a partial measure. Implementing DLP (D) is useful but reactive - it logs access after the fact rather than preventing compromise from an untrusted external environment.

Topics

#remote access#zero trust#security policy#network security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice