nerdexam
ExamsCAS-001Questions#55
CompTIA

CAS-001 · Question #55

CAS-001 Question #55: Real Exam Question with Answer & Explanation

The correct answer is B: An employee remotely configuring the email server at a relative's company during work hours.. Technical controls are automated mechanisms enforced by technology - firewalls, DLP, access controls, URL filtering, network monitoring. An employee remotely configuring an external email server during work hours can be detected and blocked through network-level technical control

Question

A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situation for several weeks the CISO publishes a more comprehensive security policy with associated standards. Which of the following issues could be addressed through the use of technical controls specified in the new security policy?

Options

  • AEmployees publishing negative information and stories about company management on social network
  • BAn employee remotely configuring the email server at a relative's company during work hours.
  • CEmployees posting negative comments about the company from personal phones and PDAs.
  • DExternal parties cloning some of the company's externally facing web pages and creating look-alike sites.

Explanation

Technical controls are automated mechanisms enforced by technology - firewalls, DLP, access controls, URL filtering, network monitoring. An employee remotely configuring an external email server during work hours can be detected and blocked through network-level technical controls such as egress filtering, protocol inspection, or DLP policies that flag unauthorized outbound administration traffic. Options A and C involve employees posting on social networks or personal devices - these actions occur outside the company's technical enforcement boundary (personal phones, personal accounts), so technical controls cannot realistically prevent them. Option D (external parties cloning web pages) happens on infrastructure the company does not control, so internal technical controls do not apply.

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice