nerdexam
CompTIA

CAS-001 · Question #28

The Chief Executive Officer (CEO) of a corporation decided to move all email to a cloud computing environment. The Chief Information Security Officer (CISO) was told to research the risk involved in…

The correct answer is B. Ensure logins are over an encrypted channel and obtain an NDA and an SLA from the cloud provider. Hosting email in the cloud requires both technical and contractual controls - encrypted communications protect data in transit while formal agreements with the provider establish accountability for data confidentiality and service availability.

Integration of Computing, Communications and Business Disciplines

Question

The Chief Executive Officer (CEO) of a corporation decided to move all email to a cloud computing environment. The Chief Information Security Officer (CISO) was told to research the risk involved in this environment. Which of the following measures should be implemented to minimize the risk of hosting email in the cloud?

Options

  • ARemind users that all emails with sensitive information need be encrypted and physically inspect the
  • BEnsure logins are over an encrypted channel and obtain an NDA and an SLA from the cloud provider.
  • CEnsure logins are over an encrypted channel and remind users to encrypt all emails that contain sensitive
  • DObtain an NDA from the cloud provider and remind users that all emails with sensitive information

How the community answered

(18 responses)
  • B
    83% (15)
  • C
    11% (2)
  • D
    6% (1)

Why each option

Hosting email in the cloud requires both technical and contractual controls - encrypted communications protect data in transit while formal agreements with the provider establish accountability for data confidentiality and service availability.

ARemind users that all emails with sensitive information need be encrypted and physically inspect the

Physically inspecting a cloud provider's infrastructure is generally not feasible for a cloud customer and does not constitute a scalable or contractually enforceable security measure.

BEnsure logins are over an encrypted channel and obtain an NDA and an SLA from the cloud provider.Correct

Ensuring logins occur over an encrypted channel (such as TLS) protects credentials and session data from interception, while obtaining a Non-Disclosure Agreement (NDA) legally obligates the cloud provider to protect company data confidentiality, and a Service Level Agreement (SLA) defines performance, availability, and security commitments - together these address both technical and governance risks of cloud email hosting.

CEnsure logins are over an encrypted channel and remind users to encrypt all emails that contain sensitive

Reminding users to encrypt sensitive emails is an informal control that lacks enforcement and does not establish any contractual accountability with the cloud provider for data protection.

DObtain an NDA from the cloud provider and remind users that all emails with sensitive information

An NDA alone without encryption of the login channel leaves credentials and data vulnerable to interception, and user reminders do not substitute for enforceable technical controls.

Concept tested: Cloud email security controls - encryption and provider agreements

Source: https://csrc.nist.gov/publications/detail/sp/800-144/final

Topics

#cloud security#email security#SLA#NDA

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice