CAS-002 · Question #719
The helpdesk department desires to roll out a remote support application for internal use on all company computers. This tool should allow remote desktop sharing, system log gathering, chat…
The correct answer is B. What accountability is built into the remote support application? Accountability - ensuring all privileged actions are logged and attributed to specific users - is the highest-priority risk concern for a remote support tool with broad access to every company computer.
Question
The helpdesk department desires to roll out a remote support application for internal use on all company computers. This tool should allow remote desktop sharing, system log gathering, chat, hardware logging, inventory management, and remote registry access. The risk management team has been asked to review vendor responses to the RFQ. Which of the following questions is the MOST important?
Options
- AWhat are the protections against MITM?
- BWhat accountability is built into the remote support application?
- CWhat encryption standards are used in tracking database?
- DWhat snapshot or "undo" features are present in the application?
- EWhat encryption standards are used in remote desktop and file transfer functionality?
How the community answered
(33 responses)- A3% (1)
- B67% (22)
- C9% (3)
- D3% (1)
- E18% (6)
Why each option
Accountability - ensuring all privileged actions are logged and attributed to specific users - is the highest-priority risk concern for a remote support tool with broad access to every company computer.
MITM protection is important but is substantially addressed by strong encryption of remote desktop and file transfer traffic, which is covered more directly by option E.
The described tool can access remote desktops, system logs, hardware inventory, and the registry, representing extremely broad privileged access across the entire organization. Built-in accountability features such as session recording, action logging, and user attribution are the most critical control because they enable detection and investigation of misuse, insider threats, or unauthorized actions. Without accountability, there is no forensic trail for any of the powerful operations the tool can perform.
Encrypting the tracking database protects stored inventory data at rest, but this is a lower-risk concern compared to ensuring that every privileged remote session action is logged and attributable to an individual.
Snapshot and undo features address accidental configuration changes but provide no security accountability and do not prevent or detect malicious use of the tool's privileged capabilities.
Encryption of remote desktop and file transfer protects data in transit and is a baseline technical requirement, but it does not address who did what during a session, making it less critical than accountability for a high-privilege internal tool.
Concept tested: Accountability and audit logging for privileged remote access tools
Source: https://csrc.nist.gov/publications/detail/sp/800-46/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.