CAS-002 · Question #572
A system architect has the following constraints from the customer: - Confidentiality, Integrity, and Availability (CIA) are all of equal importance. - Average availability must be at least 6 nines…
The correct answer is D. Enforcement of security policies on mobile/remote devices, standard images and device. When all devices must support collaboration, VoIP, and achieve 6-nines availability under equal CIA weighting, enforcing security policies with standard images across all device types provides the most balanced and comprehensive control.
Question
A system architect has the following constraints from the customer:
- Confidentiality, Integrity, and Availability (CIA) are all of equal
importance.
- Average availability must be at least 6 nines (99.9999%).
- All devices must support collaboration with every other user device.
- All devices must be VoIP and teleconference ready.
Which of the following security controls is the BEST to apply to this architecture?
Options
- ADeployment of multiple standard images based on individual hardware configurations,
- BEnforcement of strict network access controls and bandwidth minimization techniques, a
- CDeployment of a unified VDI across all devices, SSD RAID in all servers, multiple identical
- DEnforcement of security policies on mobile/remote devices, standard images and device
How the community answered
(24 responses)- A4% (1)
- B17% (4)
- C13% (3)
- D67% (16)
Why each option
When all devices must support collaboration, VoIP, and achieve 6-nines availability under equal CIA weighting, enforcing security policies with standard images across all device types provides the most balanced and comprehensive control.
Multiple images based on individual hardware configurations introduces inconsistency and increases the attack surface, conflicting with the need for uniform security across all collaborating devices.
Strict bandwidth minimization techniques directly undermine the VoIP and teleconference readiness requirement, as real-time multimedia traffic requires adequate, prioritized bandwidth.
A centralized VDI introduces a single point of failure that is difficult to achieve 6-nines availability for, and SSD RAID alone does not address the full CIA triad or the mobile/remote device security requirement.
Enforcing security policies across all devices including mobile and remote endpoints ensures confidentiality and integrity are maintained uniformly, while standard images create consistent, hardened baselines that reduce configuration drift and vulnerabilities. This approach directly addresses the requirement for all devices to support VoIP and collaboration by standardizing the software environment across the fleet. Standard images also facilitate rapid redeployment and recovery, supporting high-availability goals without centralizing risk into a single infrastructure component.
Concept tested: Security architecture balancing CIA, availability, and unified device policy
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.