nerdexam
CompTIA

CAS-002 · Question #134

A financial institution wants to reduce the costs associated with managing and troubleshooting employees' desktops and applications, while keeping employees from copying data onto external storage…

The correct answer is C. Implement VDI and disable hardware and storage mapping from the thin client. VDI with disabled hardware and storage mapping on thin clients centralizes desktop management while technically blocking data exfiltration to external removable storage.

Technical Integration of Enterprise Components

Question

A financial institution wants to reduce the costs associated with managing and troubleshooting employees' desktops and applications, while keeping employees from copying data onto external storage. The Chief Information Officer (CIO) has asked the security team to evaluate four solutions submitted by the change management group. Which of the following BEST accomplishes this task?

Options

  • AImplement desktop virtualization and encrypt all sensitive data at rest and in transit.
  • BImplement server virtualization and move the application from the desktop to the server.
  • CImplement VDI and disable hardware and storage mapping from the thin client.
  • DMove the critical applications to a private cloud and disable VPN and tunneling.

How the community answered

(49 responses)
  • A
    8% (4)
  • B
    4% (2)
  • C
    71% (35)
  • D
    16% (8)

Why each option

VDI with disabled hardware and storage mapping on thin clients centralizes desktop management while technically blocking data exfiltration to external removable storage.

AImplement desktop virtualization and encrypt all sensitive data at rest and in transit.

Encrypting data at rest and in transit does not prevent a user from copying data to external storage if hardware and USB mapping remain enabled on the desktop.

BImplement server virtualization and move the application from the desktop to the server.

Server virtualization moves applications server-side but does not provide centralized full desktop management or block users from copying files from their local endpoint to external media.

CImplement VDI and disable hardware and storage mapping from the thin client.Correct

VDI centralizes desktop delivery, patching, and application management, significantly reducing per-device administrative overhead and cost. Disabling hardware and storage mapping on the thin client prevents users from redirecting USB drives or external disks through the virtual session, directly blocking the removable media exfiltration vector while keeping all data on company infrastructure.

DMove the critical applications to a private cloud and disable VPN and tunneling.

Moving applications to a private cloud and disabling VPN does not deliver centralized desktop management or a technical control preventing external storage device usage.

Concept tested: VDI thin client storage mapping controls for data loss prevention

Source: https://csrc.nist.gov/publications/detail/sp/800-125b/final

Topics

#VDI#desktop virtualization#data loss prevention#thin client

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice