nerdexam
CompTIA

CAS-002 · Question #170

Several business units have requested the ability to use collaborative web-based meeting places with third party vendors. Generally these require user registration, installation of client-based…

The correct answer is D. Evaluate several meeting providers. When business units need third-party web collaboration tools, evaluating multiple providers allows the organization to select one that balances functionality with security requirements before any deployment.

Enterprise Security

Question

Several business units have requested the ability to use collaborative web-based meeting places with third party vendors. Generally these require user registration, installation of client-based ActiveX or Java applets, and also the ability for the user to share their desktop in read-only or read-write mode. In order to ensure that information security is not compromised, which of the following controls is BEST suited to this situation?

Options

  • ADisallow the use of web-based meetings as this could lead to vulnerable client-side
  • BHire an outside consultant firm to perform both a quantitative and a qualitative risk-based
  • CAllow the use of web-based meetings, but put controls in place to ensure that the use of
  • DEvaluate several meeting providers.

How the community answered

(42 responses)
  • A
    19% (8)
  • B
    5% (2)
  • C
    10% (4)
  • D
    67% (28)

Why each option

When business units need third-party web collaboration tools, evaluating multiple providers allows the organization to select one that balances functionality with security requirements before any deployment.

ADisallow the use of web-based meetings as this could lead to vulnerable client-side

Disallowing web-based meetings entirely fails to meet the stated business need and applies an overly restrictive control that does not balance security with business requirements.

BHire an outside consultant firm to perform both a quantitative and a qualitative risk-based

Hiring a consultant for a risk assessment is a supporting activity, not the primary control, and does not directly address selection and governance of a meeting platform.

CAllow the use of web-based meetings, but put controls in place to ensure that the use of

Allowing meetings with unspecified controls is premature without first evaluating providers to understand the specific risks and which controls are actually applicable.

DEvaluate several meeting providers.Correct

Evaluating several meeting providers allows the organization to compare security features, compliance certifications, and risk profiles before committing to a solution. This due-diligence approach ensures the chosen platform meets both the business need for collaboration and the organization's information security requirements. It avoids both the extreme of outright prohibition and the risk of deploying an unvetted tool.

Concept tested: Third-party service security evaluation and vendor risk management

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf

Topics

#third-party risk#web collaboration#ActiveX controls#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice