CAS-002 · Question #838
A security administrator has noticed that an increased number of employees' workstations are becoming infected with malware. The company deploys an enterprise antivirus system as well as a web…
The correct answer is D. Block cloud-based storage software on the company network. With malicious websites and external storage already blocked, cloud-based storage applications represent the next unmitigated technical download vector for malware.
Question
A security administrator has noticed that an increased number of employees' workstations are becoming infected with malware. The company deploys an enterprise antivirus system as well as a web content filter, which blocks access to malicious web sites where malware files can be downloaded. Additionally, the company implements technical measures to disable external storage. Which of the following is a technical control that the security administrator should implement next to reduce malware infection?
Options
- AImplement an Acceptable Use Policy which addresses malware downloads.
- BDeploy a network access control system with a persistent agent.
- CEnforce mandatory security awareness training for all employees and contractors.
- DBlock cloud-based storage software on the company network.
How the community answered
(32 responses)- A6% (2)
- B9% (3)
- C3% (1)
- D81% (26)
Why each option
With malicious websites and external storage already blocked, cloud-based storage applications represent the next unmitigated technical download vector for malware.
An Acceptable Use Policy is an administrative control, not a technical control, and relies on employee compliance rather than enforcing any technical restriction on malware downloads.
A network access control system with a persistent agent validates endpoint compliance before granting network access but does not specifically block cloud storage applications or other malware download vectors reachable from a compliant device.
Security awareness training is an administrative and educational control that depends on human behavior, not a technical mechanism that actively prevents malware from entering the network.
Cloud-based storage services such as Dropbox, Google Drive, and OneDrive can host malware files and deliver them without triggering filters targeting known malicious domains, bypassing the existing web content filter. Blocking these applications as a technical control eliminates this remaining download channel and is consistent with the already-implemented technical measure of disabling external storage, closing a parallel exfiltration and ingestion path.
Concept tested: Technical controls blocking cloud storage malware vectors
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.