nerdexam
CompTIA

CAS-002 · Question #10

Employees have recently requested remote access to corporate email and shared drives. Remote access has never been offered; however, the need to improve productivity and rapidly responding to…

The correct answer is C. Plan and develop security policies based on the assumption that external environments have. When introducing remote access, security policy and controls should be built on the assumption that external environments are untrusted and potentially hostile, implementing a zero-trust foundation.

Enterprise Security

Question

Employees have recently requested remote access to corporate email and shared drives. Remote access has never been offered; however, the need to improve productivity and rapidly responding to customer demands means staff now requires remote access. Which of the following controls will BEST protect the corporate network?

Options

  • ADevelop a security policy that defines remote access requirements.
  • BSecure remote access systems to ensure shared drives are read only and access is provided
  • CPlan and develop security policies based on the assumption that external environments have
  • DImplement a DLP program to log data accessed by users connecting via remote access.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    71% (20)
  • D
    18% (5)

Why each option

When introducing remote access, security policy and controls should be built on the assumption that external environments are untrusted and potentially hostile, implementing a zero-trust foundation.

ADevelop a security policy that defines remote access requirements.

Developing a security policy that merely defines remote access requirements is an incomplete administrative measure and does not actively enforce protections or establish a security posture.

BSecure remote access systems to ensure shared drives are read only and access is provided

Making shared drives read-only is a narrow data access restriction that addresses only one attack vector and does not provide comprehensive protection for the corporate network.

CPlan and develop security policies based on the assumption that external environments haveCorrect

Planning security policies based on the assumption that external environments are compromised or untrusted embodies a zero-trust security model - every connection from outside the perimeter is treated as potentially hostile. This approach drives the selection of strong authentication, endpoint validation, least-privilege access, and network segmentation controls that comprehensively protect the corporate network. It sets the strategic security posture that all other specific controls should derive from.

DImplement a DLP program to log data accessed by users connecting via remote access.

A DLP program logs data access but is a detective control focused on data egress; it does not broadly protect the corporate network from the range of threats introduced by remote access.

Concept tested: Zero-trust remote access security policy design

Source: https://csrc.nist.gov/publications/detail/sp/800-207/final

Topics

#remote access#zero trust#security policy#network security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice