nerdexam
CompTIA

CAS-002 · Question #324

A security manager has received the following email from the Chief Financial Officer (CFO): "While I am concerned about the security of the proprietary financial data in our ERP application, we have…

The correct answer is D. Work with the executive management team to revise policies before allowing any remote. Before enabling remote access for a group handling sensitive financial data, security policies must be formally revised with executive management before any technical solution is deployed.

Integration of Computing, Communications and Business Disciplines

Question

A security manager has received the following email from the Chief Financial Officer (CFO):

"While I am concerned about the security of the proprietary financial data in our ERP application, we have had a lot of turnover in the accounting group and I am having a difficult time meeting our monthly performance targets. As things currently stand, we do not allow employees to work from home but this is something I am willing to allow so we can get back on track. What should we do first to securely enable this capability for my group?" Based on the information provided, which of the following would be the MOST appropriate response to the CFO?

Options

  • ARemote access to the ERP tool introduces additional security vulnerabilities and should not
  • BAllow VNC access to corporate desktops from personal computers for the users working
  • CAllow terminal services access from personal computers after the CFO provides a list of the
  • DWork with the executive management team to revise policies before allowing any remote

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    3% (1)
  • C
    3% (1)
  • D
    79% (23)

Why each option

Before enabling remote access for a group handling sensitive financial data, security policies must be formally revised with executive management before any technical solution is deployed.

ARemote access to the ERP tool introduces additional security vulnerabilities and should not

Refusing remote access outright ignores the legitimate business need and fails to offer a risk-managed alternative, which is not a constructive or complete security response.

BAllow VNC access to corporate desktops from personal computers for the users working

VNC from personal computers lacks strong authentication and channel encryption, introducing significant risk of credential theft and unauthorized access to corporate desktops.

CAllow terminal services access from personal computers after the CFO provides a list of the

Granting terminal services access based only on a CFO-provided user list bypasses formal risk assessment and policy approval, skipping the governance steps necessary for secure remote access.

DWork with the executive management team to revise policies before allowing any remoteCorrect

Policy revision requires cross-functional executive alignment to define acceptable use, risk tolerance, and security requirements before technical controls are implemented. Without updated policies, any remote access solution lacks governance backing and could expose the organization to unmanaged risk, especially given the sensitivity of ERP financial data.

Concept tested: Security policy governance before enabling remote access

Source: https://csrc.nist.gov/publications/detail/sp/800-46/rev-2/final

Topics

#remote access policy#security governance#VPN#policy revision

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice