nerdexam
CompTIA

CAS-001 · Question #55

A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situation for several…

The correct answer is B. An employee remotely configuring the email server at a relative's company during work hours. Technical controls are automated mechanisms enforced by technology - firewalls, DLP, access controls, URL filtering, network monitoring. An employee remotely configuring an external email server during work hours can be detected and blocked through network-level technical…

Enterprise Security

Question

A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situation for several weeks the CISO publishes a more comprehensive security policy with associated standards. Which of the following issues could be addressed through the use of technical controls specified in the new security policy?

Options

  • AEmployees publishing negative information and stories about company management on social network
  • BAn employee remotely configuring the email server at a relative's company during work hours.
  • CEmployees posting negative comments about the company from personal phones and PDAs.
  • DExternal parties cloning some of the company's externally facing web pages and creating look-alike sites.

How the community answered

(25 responses)
  • A
    32% (8)
  • B
    44% (11)
  • C
    16% (4)
  • D
    8% (2)

Explanation

Technical controls are automated mechanisms enforced by technology - firewalls, DLP, access controls, URL filtering, network monitoring. An employee remotely configuring an external email server during work hours can be detected and blocked through network-level technical controls such as egress filtering, protocol inspection, or DLP policies that flag unauthorized outbound administration traffic. Options A and C involve employees posting on social networks or personal devices - these actions occur outside the company's technical enforcement boundary (personal phones, personal accounts), so technical controls cannot realistically prevent them. Option D (external parties cloning web pages) happens on infrastructure the company does not control, so internal technical controls do not apply.

Topics

#technical controls#security policy enforcement#DLP#access monitoring

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice