nerdexam
CompTIA

CAS-002 · Question #850

A company has noticed recently that its corporate information has ended up on an online forum. An investigation has identified that internal employees are sharing confidential corporate information…

The correct answer is C. Security awareness compliance training for all employees D. Implement DLP on the desktop, email gateway, and web proxies. Stopping intentional insider data leakage requires both a technical control that prevents data from leaving and a behavioral control that changes employee conduct.

Enterprise Security

Question

A company has noticed recently that its corporate information has ended up on an online forum. An investigation has identified that internal employees are sharing confidential corporate information on a daily basis. Which of the following are the MOST effective security controls that can be implemented to stop the above problem? (Select TWO).

Options

  • AImplement a URL filter to block the online forum
  • BImplement NIDS on the desktop and DMZ networks
  • CSecurity awareness compliance training for all employees
  • DImplement DLP on the desktop, email gateway, and web proxies
  • EReview of security policies and procedures

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    15% (5)
  • C
    76% (25)
  • E
    6% (2)

Why each option

Stopping intentional insider data leakage requires both a technical control that prevents data from leaving and a behavioral control that changes employee conduct.

AImplement a URL filter to block the online forum

A URL filter blocking the specific forum can be trivially bypassed using personal devices, mobile hotspots, or VPNs, and does not prevent data from being shared on any other forum or channel.

BImplement NIDS on the desktop and DMZ networks

NIDS (Network Intrusion Detection System) is designed to detect external attacks and anomalous network traffic, not to inspect or block authorized internal users from sending data to permitted external sites.

CSecurity awareness compliance training for all employeesCorrect

Security awareness training directly addresses the human behavior driving the leakage by educating employees on acceptable use policies, the consequences of sharing confidential information, and their legal and contractual obligations.

DImplement DLP on the desktop, email gateway, and web proxiesCorrect

DLP (Data Loss Prevention) deployed at the desktop, email gateway, and web proxies creates a multi-layered technical barrier that detects and blocks confidential data from being transmitted regardless of the channel employees attempt to use.

EReview of security policies and procedures

Reviewing security policies and procedures is an administrative activity that does not directly prevent the behavior - employees are already violating existing policies, so a review alone does not stop ongoing leakage.

Concept tested: DLP and security awareness to prevent insider data leakage

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#DLP#insider threat#security awareness training#data exfiltration prevention

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice