nerdexam
CompTIA

CAS-002 · Question #694

An employee was terminated and promptly escorted to their exit interview, after which the employee left the building. It was later discovered that this employee had started a consulting business…

The correct answer is B. Human Resources E. IT Management. Preventing recurrence of a terminated employee's data exfiltration via USB requires both Human Resources to fix offboarding policy and IT Management to implement technical controls.

Integration of Computing, Communications and Business Disciplines

Question

An employee was terminated and promptly escorted to their exit interview, after which the employee left the building. It was later discovered that this employee had started a consulting business using screen shots of their work at the company which included live customer data. This information had been removed through the use of a USB device. After this incident, it was determined a process review must be conducted to ensure this issue does not recur. Which of the following business areas should primarily be involved in this discussion? (Select TWO).

Options

  • ADatabase Administrator
  • BHuman Resources
  • CFinance
  • DNetwork Administrator
  • EIT Management

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    81% (38)
  • C
    13% (6)
  • D
    4% (2)

Why each option

Preventing recurrence of a terminated employee's data exfiltration via USB requires both Human Resources to fix offboarding policy and IT Management to implement technical controls.

ADatabase Administrator

Database administrators manage data access within database systems but do not set organizational offboarding policy or determine endpoint device control strategies.

BHuman ResourcesCorrect

Human Resources must review and strengthen termination procedures - including immediate system access revocation and clear acceptable use policies that govern data removal by departing employees.

CFinance

Finance has no relevant authority or responsibility over employee termination procedures, data handling policies, or IT security controls.

DNetwork Administrator

Network administrators manage network infrastructure and connectivity but are not primarily responsible for endpoint DLP policy decisions or the offboarding process for terminated employees.

EIT ManagementCorrect

IT Management is responsible for implementing technical preventive controls such as USB port restrictions, endpoint data loss prevention (DLP) tools, and ensuring that security policies are enforced at the system level to block unauthorized data exfiltration.

Concept tested: Data loss prevention policy ownership after insider data theft

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#data exfiltration#DLP#USB policy#insider threat

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice