nerdexam
CompTIA

CAS-001 · Question #291

Staff from the sales department have administrator rights to their corporate standard operating environment, and often connect their work laptop to customer networks when onsite during meetings and…

The correct answer is A. Implement a network access control (NAC) solution that assesses the posture of the laptop before. A Network Access Control (NAC) solution performs automated posture assessment - checking for current patches, AV signatures, firewall status, and policy compliance - before permitting a device to rejoin the corporate LAN. This directly addresses the scenario's risk: a laptop…

Enterprise Security

Question

Staff from the sales department have administrator rights to their corporate standard operating environment, and often connect their work laptop to customer networks when onsite during meetings and presentations. This increases the risk and likelihood of a security incident when the sales staff reconnects to the corporate LAN. Which of the following controls would BEST protect the corporate network?

Options

  • AImplement a network access control (NAC) solution that assesses the posture of the laptop before
  • BUse an independent consulting firm to provide regular network vulnerability assessments and biannually
  • CProvide sales staff with a separate laptop with no administrator access just for sales visits.
  • DUpdate the acceptable use policy and ensure sales staff read and acknowledge the policy.

How the community answered

(18 responses)
  • A
    78% (14)
  • B
    11% (2)
  • C
    6% (1)
  • D
    6% (1)

Explanation

A Network Access Control (NAC) solution performs automated posture assessment - checking for current patches, AV signatures, firewall status, and policy compliance - before permitting a device to rejoin the corporate LAN. This directly addresses the scenario's risk: a laptop that may have been exposed to a hostile customer network is automatically evaluated and either remediated or quarantined before it can threaten the corporate environment. Option B (periodic vulnerability assessments) is a detective/advisory control and does nothing in real time when a laptop reconnects. Option C (a separate sales laptop) reduces risk but is operationally expensive and does not protect the corporate LAN itself. Option D (updating the AUP) is an administrative control that relies entirely on human compliance and provides no technical enforcement.

Topics

#network access control#endpoint posture#remote access#corporate LAN

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice