CAS-002 · Question #774
An analyst connects to a company web conference hosted on allowed to join, without providing identifying information. The topics covered during the web conference are considered proprietary to the…
The correct answer is C. Unauthenticated users could present a risk to the confidentiality of the company's information. Allowing unauthenticated guests to join a web conference containing proprietary information is a confidentiality risk, because the identity and authorization level of attendees cannot be verified. The core concern is unauthorized disclosure of sensitive company data.
Question
An analyst connects to a company web conference hosted on allowed to join, without providing identifying information. The topics covered during the web conference are considered proprietary to the company. Which of the following security concerns does the analyst present to management?
Options
- AGuest users could present a risk to the integrity of the company's information
- BAuthenticated users could sponsor guest access that was previously approved by management
- CUnauthenticated users could present a risk to the confidentiality of the company's information
- DMeeting owners could sponsor guest access if they have passed a background check
How the community answered
(31 responses)- A3% (1)
- B3% (1)
- C87% (27)
- D6% (2)
Why each option
Allowing unauthenticated guests to join a web conference containing proprietary information is a confidentiality risk, because the identity and authorization level of attendees cannot be verified. The core concern is unauthorized disclosure of sensitive company data.
Integrity refers to unauthorized modification of data; a passive, unauthenticated listener cannot alter the information being discussed, so integrity is not the primary concern in this scenario.
This statement describes a management-approved sponsorship process rather than identifying a security concern; it frames the situation as an acceptable control rather than a risk.
When a user joins a web conference without providing identifying information, the system cannot verify who that person is or whether they are authorized to hear proprietary content. This creates a direct confidentiality risk - sensitive company information may be exposed to unknown third parties who have no established need-to-know, violating the principle of least privilege for information access.
This describes a hypothetical access control policy (background-check-based sponsorship) rather than identifying a present security concern or risk posed by the current unauthenticated access.
Concept tested: Unauthenticated access and information confidentiality risk
Source: https://csrc.nist.gov/glossary/term/confidentiality
Topics
Community Discussion
No community discussion yet for this question.