CAS-002 · Question #694
An employee was terminated and promptly escorted to their exit interview, after which the employee left the building. It was later discovered that this employee had started a consulting business…
The correct answer is B. Human Resources E. IT Management. Preventing recurrence of a terminated employee's data exfiltration via USB requires both Human Resources to fix offboarding policy and IT Management to implement technical controls.
Question
An employee was terminated and promptly escorted to their exit interview, after which the employee left the building. It was later discovered that this employee had started a consulting business using screen shots of their work at the company which included live customer data. This information had been removed through the use of a USB device. After this incident, it was determined a process review must be conducted to ensure this issue does not recur. Which of the following business areas should primarily be involved in this discussion? (Select TWO).
Options
- ADatabase Administrator
- BHuman Resources
- CFinance
- DNetwork Administrator
- EIT Management
How the community answered
(47 responses)- A2% (1)
- B81% (38)
- C13% (6)
- D4% (2)
Why each option
Preventing recurrence of a terminated employee's data exfiltration via USB requires both Human Resources to fix offboarding policy and IT Management to implement technical controls.
Database administrators manage data access within database systems but do not set organizational offboarding policy or determine endpoint device control strategies.
Human Resources must review and strengthen termination procedures - including immediate system access revocation and clear acceptable use policies that govern data removal by departing employees.
Finance has no relevant authority or responsibility over employee termination procedures, data handling policies, or IT security controls.
Network administrators manage network infrastructure and connectivity but are not primarily responsible for endpoint DLP policy decisions or the offboarding process for terminated employees.
IT Management is responsible for implementing technical preventive controls such as USB port restrictions, endpoint data loss prevention (DLP) tools, and ensuring that security policies are enforced at the system level to block unauthorized data exfiltration.
Concept tested: Data loss prevention policy ownership after insider data theft
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.