CAS-001 · Question #66
A system architect has the following constraints from the customer: - Confidentiality, Integrity, and Availability (CIA) are all of equal importance. - Average availability must be at least 6 nines…
The correct answer is D. Enforcement of security policies on mobile/remote devices, standard images and device hardware. The question evaluates the best security architecture to simultaneously satisfy strict availability, CIA, device collaboration, and VoIP readiness requirements.
Question
A system architect has the following constraints from the customer:
- Confidentiality, Integrity, and Availability (CIA) are all of equal
importance.
- Average availability must be at least 6 nines (99.9999%).
- All devices must support collaboration with every other user device.
- All devices must be VoIP and teleconference ready.
Which of the following security controls is the BEST to apply to this architecture?
Options
- ADeployment of multiple standard images based on individual hardware configurations, employee choice
- BEnforcement of strict network access controls and bandwidth minimization techniques, a single standard
- CDeployment of a unified VDI across all devices, SSD RAID in all servers, multiple identical hot sites,
- DEnforcement of security policies on mobile/remote devices, standard images and device hardware
How the community answered
(53 responses)- A15% (8)
- B34% (18)
- C8% (4)
- D43% (23)
Why each option
The question evaluates the best security architecture to simultaneously satisfy strict availability, CIA, device collaboration, and VoIP readiness requirements.
Allowing employee hardware choice with multiple images introduces configuration inconsistency, making it impossible to guarantee uniform VoIP readiness or enforce consistent security policies.
Bandwidth minimization techniques would degrade real-time VoIP and teleconference quality, directly conflicting with the VoIP and teleconference readiness requirement.
VDI centralizes endpoint functionality on servers and the network, introducing dependencies that create risk for achieving 6 nines uptime and may add latency that degrades real-time VoIP performance.
Standard images and hardware ensure every device has a uniform, tested configuration that natively supports VoIP, teleconferencing, and cross-device collaboration. Enforcing security policies on mobile and remote devices maintains consistent CIA protection across all endpoints regardless of location. This approach provides scalable, manageable security without introducing centralized single points of failure that would threaten the required 6 nines availability.
Concept tested: High-availability unified endpoint security architecture
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.