nerdexam
CompTIA

CAS-002 · Question #719

The helpdesk department desires to roll out a remote support application for internal use on all company computers. This tool should allow remote desktop sharing, system log gathering, chat…

The correct answer is B. What accountability is built into the remote support application? Accountability - ensuring all privileged actions are logged and attributed to specific users - is the highest-priority risk concern for a remote support tool with broad access to every company computer.

Research and Analysis

Question

The helpdesk department desires to roll out a remote support application for internal use on all company computers. This tool should allow remote desktop sharing, system log gathering, chat, hardware logging, inventory management, and remote registry access. The risk management team has been asked to review vendor responses to the RFQ. Which of the following questions is the MOST important?

Options

  • AWhat are the protections against MITM?
  • BWhat accountability is built into the remote support application?
  • CWhat encryption standards are used in tracking database?
  • DWhat snapshot or "undo" features are present in the application?
  • EWhat encryption standards are used in remote desktop and file transfer functionality?

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    67% (22)
  • C
    9% (3)
  • D
    3% (1)
  • E
    18% (6)

Why each option

Accountability - ensuring all privileged actions are logged and attributed to specific users - is the highest-priority risk concern for a remote support tool with broad access to every company computer.

AWhat are the protections against MITM?

MITM protection is important but is substantially addressed by strong encryption of remote desktop and file transfer traffic, which is covered more directly by option E.

BWhat accountability is built into the remote support application?Correct

The described tool can access remote desktops, system logs, hardware inventory, and the registry, representing extremely broad privileged access across the entire organization. Built-in accountability features such as session recording, action logging, and user attribution are the most critical control because they enable detection and investigation of misuse, insider threats, or unauthorized actions. Without accountability, there is no forensic trail for any of the powerful operations the tool can perform.

CWhat encryption standards are used in tracking database?

Encrypting the tracking database protects stored inventory data at rest, but this is a lower-risk concern compared to ensuring that every privileged remote session action is logged and attributable to an individual.

DWhat snapshot or "undo" features are present in the application?

Snapshot and undo features address accidental configuration changes but provide no security accountability and do not prevent or detect malicious use of the tool's privileged capabilities.

EWhat encryption standards are used in remote desktop and file transfer functionality?

Encryption of remote desktop and file transfer protects data in transit and is a baseline technical requirement, but it does not address who did what during a session, making it less critical than accountability for a high-privilege internal tool.

Concept tested: Accountability and audit logging for privileged remote access tools

Source: https://csrc.nist.gov/publications/detail/sp/800-46/rev-2/final

Topics

#risk management#remote access accountability#RFQ evaluation#vendor assessment

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice