CAS-001 · Question #494
A security manager has received the following email from the Chief Financial Officer (CFO): "While I am concerned about the security of the proprietary financial data in our ERP application, we have…
The correct answer is D. Work with the executive management team to revise policies before allowing any remote access. The MOST appropriate first response is to work with executive management to revise policies before enabling remote access (D). Enabling remote access to sensitive financial ERP systems is a significant security policy change that cannot be done ad hoc. Policies must define…
Question
A security manager has received the following email from the Chief Financial Officer (CFO):
"While I am concerned about the security of the proprietary financial data in our ERP application, we have had a lot of turnover in the accounting group and I am having a difficult time meeting our monthly performance targets. As things currently stand, we do not allow employees to work from home but this is something I am willing to allow so we can get back on track. What should we do first to securely enable this capability for my group?" Based on the information provided, which of the following would be the MOST appropriate response to the CFO?
Options
- ARemote access to the ERP tool introduces additional security vulnerabilities and should not be
- BAllow VNC access to corporate desktops from personal computers for the users working from
- CAllow terminal services access from personal computers after the CFO provides a list of the users
- DWork with the executive management team to revise policies before allowing any remote access.
How the community answered
(33 responses)- A6% (2)
- B12% (4)
- C30% (10)
- D52% (17)
Explanation
The MOST appropriate first response is to work with executive management to revise policies before enabling remote access (D). Enabling remote access to sensitive financial ERP systems is a significant security policy change that cannot be done ad hoc. Policies must define acceptable use, required security controls, approved devices, and access scope before implementation begins. Option A is overly restrictive and dismisses the business need. Option B (VNC from personal computers) is insecure - personal devices lack corporate security controls and VNC has known vulnerabilities. Option C (terminal services from a user list) skips the policy step and bypasses proper governance. Policy revision ensures proper authorization, risk acceptance, and documented controls.
Topics
Community Discussion
No community discussion yet for this question.