CAS-002 · Question #134
A financial institution wants to reduce the costs associated with managing and troubleshooting employees' desktops and applications, while keeping employees from copying data onto external storage…
The correct answer is C. Implement VDI and disable hardware and storage mapping from the thin client. VDI with disabled hardware and storage mapping on thin clients centralizes desktop management while technically blocking data exfiltration to external removable storage.
Question
A financial institution wants to reduce the costs associated with managing and troubleshooting employees' desktops and applications, while keeping employees from copying data onto external storage. The Chief Information Officer (CIO) has asked the security team to evaluate four solutions submitted by the change management group. Which of the following BEST accomplishes this task?
Options
- AImplement desktop virtualization and encrypt all sensitive data at rest and in transit.
- BImplement server virtualization and move the application from the desktop to the server.
- CImplement VDI and disable hardware and storage mapping from the thin client.
- DMove the critical applications to a private cloud and disable VPN and tunneling.
How the community answered
(49 responses)- A8% (4)
- B4% (2)
- C71% (35)
- D16% (8)
Why each option
VDI with disabled hardware and storage mapping on thin clients centralizes desktop management while technically blocking data exfiltration to external removable storage.
Encrypting data at rest and in transit does not prevent a user from copying data to external storage if hardware and USB mapping remain enabled on the desktop.
Server virtualization moves applications server-side but does not provide centralized full desktop management or block users from copying files from their local endpoint to external media.
VDI centralizes desktop delivery, patching, and application management, significantly reducing per-device administrative overhead and cost. Disabling hardware and storage mapping on the thin client prevents users from redirecting USB drives or external disks through the virtual session, directly blocking the removable media exfiltration vector while keeping all data on company infrastructure.
Moving applications to a private cloud and disabling VPN does not deliver centralized desktop management or a technical control preventing external storage device usage.
Concept tested: VDI thin client storage mapping controls for data loss prevention
Source: https://csrc.nist.gov/publications/detail/sp/800-125b/final
Topics
Community Discussion
No community discussion yet for this question.