nerdexam
CompTIA

CAS-002 · Question #172

A security consultant is called into a small advertising business to recommend which security policies and procedures would be most helpful to the business. The business is comprised of 20…

The correct answer is A. Password Policy B. Data Classification Policy. For a small 20-person business with employee and client data but no remote server access, a Password Policy and Data Classification Policy are the most foundational and broadly applicable controls to implement first.

Enterprise Security

Question

A security consultant is called into a small advertising business to recommend which security policies and procedures would be most helpful to the business. The business is comprised of 20 employees, operating off of two shared servers. One server houses employee data and the other houses client data. All machines are on the same local network. Often these employees must work remotely from client sites, but do not access either of the servers remotely. Assuming no security policies or procedures are in place right now, which of the following would be the MOST applicable for implementation? (Select TWO).

Options

  • APassword Policy
  • BData Classification Policy
  • CWireless Access Procedure
  • DVPN Policy
  • EDatabase Administrative Procedure

How the community answered

(45 responses)
  • A
    78% (35)
  • C
    4% (2)
  • D
    11% (5)
  • E
    7% (3)

Why each option

For a small 20-person business with employee and client data but no remote server access, a Password Policy and Data Classification Policy are the most foundational and broadly applicable controls to implement first.

APassword PolicyCorrect

A Password Policy is the most universally applicable security control for any organization, protecting access to both shared servers and individual workstations with minimal complexity and immediate effect.

BData Classification PolicyCorrect

A Data Classification Policy is critical here because the company maintains two distinct categories of sensitive data - employee data and client data on separate servers - and classification helps prioritize appropriate protections for each category.

CWireless Access Procedure

A Wireless Access Procedure is not applicable because the scenario makes no mention of wireless infrastructure in this small office environment.

DVPN Policy

A VPN Policy is unnecessary because the scenario explicitly states that employees do not access either server remotely when working from client sites.

EDatabase Administrative Procedure

A Database Administrative Procedure is too operationally complex and granular for a 20-person company and is not among the most critical foundational policies needed.

Concept tested: Foundational security policy prioritization for small businesses

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-12r1.pdf

Topics

#password policy#data classification#security policy#small business security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice