nerdexam
CompTIA

CAS-003 · Question #3

A large enterprise with thousands of users is experiencing a relatively high frequency of malicious activity from the insider threats. Much of the activity appears to involve internal reconnaissance…

The correct answer is C. Enforce command shell restrictions via group policies for all workstations by default to limit which D. Modify the existing rules of behavior to include an explicit statement prohibiting users from. Restricting command shell access via group policy limits the reconnaissance tools available to insiders, and explicit rules of behavior create policy-based deterrence against malicious activity.

Enterprise Security Operations

Question

A large enterprise with thousands of users is experiencing a relatively high frequency of malicious activity from the insider threats. Much of the activity appears to involve internal reconnaissance that results in targeted attacks against privileged users and network file shares. Given this scenario, which of the following would MOST likely prevent or deter these attacks? (Choose two.)

Options

  • AConduct role-based training for privileged users that highlights common threats against them and
  • BIncrease the frequency at which host operating systems are scanned for vulnerabilities, and
  • CEnforce command shell restrictions via group policies for all workstations by default to limit which
  • DModify the existing rules of behavior to include an explicit statement prohibiting users from
  • EFor all workstations, implement full-disk encryption and configure UEFI instances to require
  • FImplement application blacklisting enforced by the operating systems of all machines in the

How the community answered

(51 responses)
  • A
    24% (12)
  • B
    14% (7)
  • C
    55% (28)
  • E
    6% (3)
  • F
    2% (1)

Why each option

Restricting command shell access via group policy limits the reconnaissance tools available to insiders, and explicit rules of behavior create policy-based deterrence against malicious activity.

AConduct role-based training for privileged users that highlights common threats against them and

Role-based training raises awareness but does not technically prevent or deter reconnaissance activity from occurring.

BIncrease the frequency at which host operating systems are scanned for vulnerabilities, and

Increasing vulnerability scan frequency helps identify weaknesses but does not prevent an already-present insider from performing reconnaissance.

CEnforce command shell restrictions via group policies for all workstations by default to limit whichCorrect

Enforcing command shell restrictions via group policy prevents insiders from running enumeration utilities (net, whoami, dir, etc.) used during internal reconnaissance, directly limiting the attack surface for the observed behavior.

DModify the existing rules of behavior to include an explicit statement prohibiting users fromCorrect

Explicitly stating prohibited behaviors in rules of behavior creates a documented, signed deterrent and provides grounds for disciplinary or legal action, deterring opportunistic insider threats.

EFor all workstations, implement full-disk encryption and configure UEFI instances to require

Full-disk encryption and UEFI protections defend against physical theft and offline attacks, not against authenticated insider reconnaissance over the network.

FImplement application blacklisting enforced by the operating systems of all machines in the

Application blacklisting blocks known malicious executables but insiders can still use built-in OS tools for reconnaissance unless shell access is restricted.

Concept tested: Mitigating insider threat reconnaissance with policy and technical controls

Source: https://www.cisa.gov/topics/physical-security/insider-threat-mitigation

Topics

#insider threat#privilege escalation#group policy#security awareness training

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice