CAS-003 · Question #357
As a result of an acquisition, a new development team is being integrated into the company. The development team has BYOD laptops with IDEs installed, build servers, and code repositories that…
The correct answer is D. Rights management E. SSL VPN F. NAC. Deploying Rights Management, SSL VPN, and NAC together collectively satisfies all four stated requirements: protecting sensitive files, providing access to corporate applications over existing infrastructure, and enforcing acceptable use policies on BYOD devices.
Question
Options
- AIPSec VPN
- BHIDS
- CWireless controller
- DRights management
- ESSL VPN
- FNAC
- GWAF
- HLoad balancer
How the community answered
(48 responses)- A2% (1)
- B8% (4)
- C17% (8)
- D67% (32)
- G4% (2)
- H2% (1)
Why each option
Deploying Rights Management, SSL VPN, and NAC together collectively satisfies all four stated requirements: protecting sensitive files, providing access to corporate applications over existing infrastructure, and enforcing acceptable use policies on BYOD devices.
IPSec VPN requires specific client software and precise device configuration that conflicts with an unmanaged BYOD model, making SSL VPN the superior and more practical choice here.
A Host-based Intrusion Detection System (HIDS) cannot be reliably installed or maintained on BYOD devices the organization does not own or control.
A wireless controller manages Wi-Fi infrastructure, but the team was provided a dedicated separate internet connection and no wireless network management requirement was stated.
Rights Management (IRM/DRM) directly satisfies requirement 3 by enforcing persistent encryption and usage controls on sensitive files regardless of where they are stored or copied, even on unmanaged BYOD devices.
SSL VPN satisfies requirements 1 and 4 by tunneling corporate application access over the existing internet connection without requiring changes to underlying network infrastructure, and it is well-suited for BYOD because it uses browser-based or lightweight clients.
Network Access Control (NAC) satisfies requirement 2 by evaluating device posture and enforcing acceptable use policies before granting any corporate access, which is critical for screening untrusted third-party BYOD laptops.
A WAF protects web applications from inbound external attacks but does not address BYOD device access control, file protection, or acceptable use policy enforcement.
A load balancer distributes traffic for availability and performance and does not contribute to any of the four security or access requirements described in the scenario.
Concept tested: BYOD network access controls using NAC, SSL VPN, and rights management
Source: https://csrc.nist.gov/publications/detail/sp/800-114/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.