CAS-001 · Question #55
A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situation for several…
The correct answer is B. An employee remotely configuring the email server at a relative's company during work hours. Technical controls are automated mechanisms enforced by technology - firewalls, DLP, access controls, URL filtering, network monitoring. An employee remotely configuring an external email server during work hours can be detected and blocked through network-level technical…
Question
A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situation for several weeks the CISO publishes a more comprehensive security policy with associated standards. Which of the following issues could be addressed through the use of technical controls specified in the new security policy?
Options
- AEmployees publishing negative information and stories about company management on social network
- BAn employee remotely configuring the email server at a relative's company during work hours.
- CEmployees posting negative comments about the company from personal phones and PDAs.
- DExternal parties cloning some of the company's externally facing web pages and creating look-alike sites.
How the community answered
(25 responses)- A32% (8)
- B44% (11)
- C16% (4)
- D8% (2)
Explanation
Technical controls are automated mechanisms enforced by technology - firewalls, DLP, access controls, URL filtering, network monitoring. An employee remotely configuring an external email server during work hours can be detected and blocked through network-level technical controls such as egress filtering, protocol inspection, or DLP policies that flag unauthorized outbound administration traffic. Options A and C involve employees posting on social networks or personal devices - these actions occur outside the company's technical enforcement boundary (personal phones, personal accounts), so technical controls cannot realistically prevent them. Option D (external parties cloning web pages) happens on infrastructure the company does not control, so internal technical controls do not apply.
Topics
Community Discussion
No community discussion yet for this question.