CAS-002 · Question #10
Employees have recently requested remote access to corporate email and shared drives. Remote access has never been offered; however, the need to improve productivity and rapidly responding to…
The correct answer is C. Plan and develop security policies based on the assumption that external environments have. When introducing remote access, security policy and controls should be built on the assumption that external environments are untrusted and potentially hostile, implementing a zero-trust foundation.
Question
Employees have recently requested remote access to corporate email and shared drives. Remote access has never been offered; however, the need to improve productivity and rapidly responding to customer demands means staff now requires remote access. Which of the following controls will BEST protect the corporate network?
Options
- ADevelop a security policy that defines remote access requirements.
- BSecure remote access systems to ensure shared drives are read only and access is provided
- CPlan and develop security policies based on the assumption that external environments have
- DImplement a DLP program to log data accessed by users connecting via remote access.
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C71% (20)
- D18% (5)
Why each option
When introducing remote access, security policy and controls should be built on the assumption that external environments are untrusted and potentially hostile, implementing a zero-trust foundation.
Developing a security policy that merely defines remote access requirements is an incomplete administrative measure and does not actively enforce protections or establish a security posture.
Making shared drives read-only is a narrow data access restriction that addresses only one attack vector and does not provide comprehensive protection for the corporate network.
Planning security policies based on the assumption that external environments are compromised or untrusted embodies a zero-trust security model - every connection from outside the perimeter is treated as potentially hostile. This approach drives the selection of strong authentication, endpoint validation, least-privilege access, and network segmentation controls that comprehensively protect the corporate network. It sets the strategic security posture that all other specific controls should derive from.
A DLP program logs data access but is a detective control focused on data egress; it does not broadly protect the corporate network from the range of threats introduced by remote access.
Concept tested: Zero-trust remote access security policy design
Source: https://csrc.nist.gov/publications/detail/sp/800-207/final
Topics
Community Discussion
No community discussion yet for this question.