nerdexam
CompTIA

CAS-002 · Question #58

Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals: - Prevent data breaches from lost/stolen assets…

The correct answer is A. Implement separation of duties; enable full encryption on USB devices and cell phones. Answer A - implementing separation of duties and enabling full encryption on USB devices and cell phones - addresses the most goals simultaneously. Full-disk encryption on portable devices directly prevents data breaches from lost or stolen assets. Encryption also prevents PII…

Enterprise Security

Question

Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals:

  • Prevent data breaches from lost/stolen assets
  • Reduce time to fulfill e-discovery requests
  • Prevent PII from leaving the network
  • Lessen the network perimeter attack surface
  • Reduce internal fraud

Which of the following solutions accomplishes the MOST of these goals?

Options

  • AImplement separation of duties; enable full encryption on USB devices and cell phones,
  • BEliminate VPN access from remote devices.
  • CCreate a change control process with stakeholder review board, implement separation of
  • DImplement outgoing mail sanitation and incoming SPAM filtering.

How the community answered

(70 responses)
  • A
    64% (45)
  • B
    6% (4)
  • C
    23% (16)
  • D
    7% (5)

Explanation

Answer A - implementing separation of duties and enabling full encryption on USB devices and cell phones - addresses the most goals simultaneously. Full-disk encryption on portable devices directly prevents data breaches from lost or stolen assets. Encryption also prevents PII from being readable if devices leave the network. Separation of duties reduces internal fraud by ensuring no single person controls an entire process. While no single answer is perfect for all five goals, A covers at least three (breach prevention, PII protection, internal fraud). Eliminating VPN (B) addresses attack surface but undermines business functionality. A change control board (C) helps fraud/change management but not asset encryption. Mail sanitation (D) helps PII/spam but not physical asset theft or fraud.

Topics

#DLP#encryption#separation of duties#e-discovery

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice