nerdexam
CompTIA

CAS-003 · Question #357

As a result of an acquisition, a new development team is being integrated into the company. The development team has BYOD laptops with IDEs installed, build servers, and code repositories that…

The correct answer is D. Rights management E. SSL VPN F. NAC. Deploying Rights Management, SSL VPN, and NAC together collectively satisfies all four stated requirements: protecting sensitive files, providing access to corporate applications over existing infrastructure, and enforcing acceptable use policies on BYOD devices.

Enterprise Security Architecture

Question

As a result of an acquisition, a new development team is being integrated into the company. The development team has BYOD laptops with IDEs installed, build servers, and code repositories that utilize SaaS. To have the team up and running effectively, a separate Internet connection has been procured. A stand up has identified the following additional requirements: 1. Reuse of the existing network infrastructure 2. Acceptable use policies to be enforced 3. Protection of sensitive files 4. Access to the corporate applications Which of the following solution components should be deployed to BEST meet the requirements? (Select three.)

Options

  • AIPSec VPN
  • BHIDS
  • CWireless controller
  • DRights management
  • ESSL VPN
  • FNAC
  • GWAF
  • HLoad balancer

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    8% (4)
  • C
    17% (8)
  • D
    67% (32)
  • G
    4% (2)
  • H
    2% (1)

Why each option

Deploying Rights Management, SSL VPN, and NAC together collectively satisfies all four stated requirements: protecting sensitive files, providing access to corporate applications over existing infrastructure, and enforcing acceptable use policies on BYOD devices.

AIPSec VPN

IPSec VPN requires specific client software and precise device configuration that conflicts with an unmanaged BYOD model, making SSL VPN the superior and more practical choice here.

BHIDS

A Host-based Intrusion Detection System (HIDS) cannot be reliably installed or maintained on BYOD devices the organization does not own or control.

CWireless controller

A wireless controller manages Wi-Fi infrastructure, but the team was provided a dedicated separate internet connection and no wireless network management requirement was stated.

DRights managementCorrect

Rights Management (IRM/DRM) directly satisfies requirement 3 by enforcing persistent encryption and usage controls on sensitive files regardless of where they are stored or copied, even on unmanaged BYOD devices.

ESSL VPNCorrect

SSL VPN satisfies requirements 1 and 4 by tunneling corporate application access over the existing internet connection without requiring changes to underlying network infrastructure, and it is well-suited for BYOD because it uses browser-based or lightweight clients.

FNACCorrect

Network Access Control (NAC) satisfies requirement 2 by evaluating device posture and enforcing acceptable use policies before granting any corporate access, which is critical for screening untrusted third-party BYOD laptops.

GWAF

A WAF protects web applications from inbound external attacks but does not address BYOD device access control, file protection, or acceptable use policy enforcement.

HLoad balancer

A load balancer distributes traffic for availability and performance and does not contribute to any of the four security or access requirements described in the scenario.

Concept tested: BYOD network access controls using NAC, SSL VPN, and rights management

Source: https://csrc.nist.gov/publications/detail/sp/800-114/rev-1/final

Topics

#BYOD#network access control#SSL VPN#rights management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice