CAS-003 · Question #254
CAS-003 Question #254: Real Exam Question with Answer & Explanation
The correct answer is B: A DLP gateway should be installed at the company border.. Web mail, Instant Messaging and personal networking sites are some of the most common means by which corporate data is leaked. Data loss prevention (DLP) is a strategy for making sure that end users do not send sensitive or critical information outside the corporate network. The
Question
Options
- AA full-system backup should be implemented to a third-party provider with strong encryption for
- BA DLP gateway should be installed at the company border.
- CStrong authentication should be implemented via external biometric devices.
- DFull-tunnel VPN should be required for all network communication.
- EFull-drive file hashing should be implemented with hashes stored on separate storage.
- FSplit-tunnel VPN should be enforced when transferring sensitive data.
Explanation
Web mail, Instant Messaging and personal networking sites are some of the most common means by which corporate data is leaked. Data loss prevention (DLP) is a strategy for making sure that end users do not send sensitive or critical information outside the corporate network. The term is also used to describe software products that help a network administrator control what data end users can transfer. DLP software products use business rules to classify and protect confidential and critical information so that unauthorized end users cannot accidentally or maliciously share data whose disclosure could put the organization at risk. For example, if an employee tried to forward a business email outside the corporate domain or upload a corporate file to a consumer cloud storage service like Dropbox, the employee would be denied permission. Full-tunnel VPN should be required for all network communication. This will ensure that all data transmitted over the network is encrypted which would prevent a malicious user accessing the data by using packet sniffing.
Community Discussion
No community discussion yet for this question.