CAS-002 · Question #850
A company has noticed recently that its corporate information has ended up on an online forum. An investigation has identified that internal employees are sharing confidential corporate information…
The correct answer is C. Security awareness compliance training for all employees D. Implement DLP on the desktop, email gateway, and web proxies. Stopping intentional insider data leakage requires both a technical control that prevents data from leaving and a behavioral control that changes employee conduct.
Question
A company has noticed recently that its corporate information has ended up on an online forum. An investigation has identified that internal employees are sharing confidential corporate information on a daily basis. Which of the following are the MOST effective security controls that can be implemented to stop the above problem? (Select TWO).
Options
- AImplement a URL filter to block the online forum
- BImplement NIDS on the desktop and DMZ networks
- CSecurity awareness compliance training for all employees
- DImplement DLP on the desktop, email gateway, and web proxies
- EReview of security policies and procedures
How the community answered
(33 responses)- A3% (1)
- B15% (5)
- C76% (25)
- E6% (2)
Why each option
Stopping intentional insider data leakage requires both a technical control that prevents data from leaving and a behavioral control that changes employee conduct.
A URL filter blocking the specific forum can be trivially bypassed using personal devices, mobile hotspots, or VPNs, and does not prevent data from being shared on any other forum or channel.
NIDS (Network Intrusion Detection System) is designed to detect external attacks and anomalous network traffic, not to inspect or block authorized internal users from sending data to permitted external sites.
Security awareness training directly addresses the human behavior driving the leakage by educating employees on acceptable use policies, the consequences of sharing confidential information, and their legal and contractual obligations.
DLP (Data Loss Prevention) deployed at the desktop, email gateway, and web proxies creates a multi-layered technical barrier that detects and blocks confidential data from being transmitted regardless of the channel employees attempt to use.
Reviewing security policies and procedures is an administrative activity that does not directly prevent the behavior - employees are already violating existing policies, so a review alone does not stop ongoing leakage.
Concept tested: DLP and security awareness to prevent insider data leakage
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.