nerdexam
CompTIA

CAS-002 · Question #661

A manager who was attending an all-day training session was overdue entering bonus and payroll information for subordinates. The manager felt the best way to get the changes entered while in…

The correct answer is A. Provide targeted security awareness training and impose termination for repeat violators. The manager's violation stemmed from a lack of security awareness rather than malicious intent, making targeted training the most proportionate and effective corrective control.

Enterprise Security

Question

A manager who was attending an all-day training session was overdue entering bonus and payroll information for subordinates. The manager felt the best way to get the changes entered while in training was to log into the payroll system, and then activate desktop sharing with a trusted subordinate. The manager granted the subordinate control of the desktop thereby giving the subordinate full access to the payroll system. The subordinate did not have authorization to be in the payroll system. Another employee reported the incident to the security team. Which of the following would be the MOST appropriate method for dealing with this issue going forward?

Options

  • AProvide targeted security awareness training and impose termination for repeat violators.
  • BBlock desktop sharing and web conferencing applications and enable use only with approval.
  • CActively monitor the data traffic for each employee using desktop sharing or web
  • DPermanently block desktop sharing and web conferencing applications and do not allow its

How the community answered

(28 responses)
  • A
    82% (23)
  • B
    4% (1)
  • C
    11% (3)
  • D
    4% (1)

Why each option

The manager's violation stemmed from a lack of security awareness rather than malicious intent, making targeted training the most proportionate and effective corrective control.

AProvide targeted security awareness training and impose termination for repeat violators.Correct

Targeted security awareness training directly addresses the root cause - the manager failed to recognize that sharing desktop control of a privileged system with an unauthorized user violates access control policy. Pairing training with a progressive discipline policy including termination for repeat offenses creates both an educational effect and a deterrent, while preserving legitimate desktop sharing capabilities for the organization.

BBlock desktop sharing and web conferencing applications and enable use only with approval.

Requiring approval for all desktop sharing is a disproportionately broad technical restriction that penalizes all users for one policy violation and does not address the underlying security awareness gap.

CActively monitor the data traffic for each employee using desktop sharing or web

Actively monitoring all desktop sharing traffic for every employee is a disproportionate surveillance measure that does not resolve the root cause and introduces significant privacy concerns.

DPermanently block desktop sharing and web conferencing applications and do not allow its

Permanently blocking all desktop sharing removes a legitimate and valuable business productivity tool from the entire organization based on a single policy violation, which is an overly punitive and operationally harmful response.

Concept tested: Security awareness training as corrective response to access policy violations

Source: https://csrc.nist.gov/publications/detail/sp/800-50/final

Topics

#security awareness training#access control#desktop sharing policy#insider threat

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice