nerdexam
CompTIA

CAS-003 · Question #454

A security assessor is working with an organization to review the policies and procedures associated with managing the organization's virtual infrastructure. During a review of the virtual…

The correct answer is C. update system implementation procedures to comply with regulations. To avoiding regulatory compliance and hiding your dual purpose systems on a different network segment incurs legal risk / exposure.

Risk Management

Question

A security assessor is working with an organization to review the policies and procedures associated with managing the organization's virtual infrastructure. During a review of the virtual environment, the assessor determines the organization is using servers to provide more than one primary function, which violates a regulatory requirement. The assessor reviews hardening guides and determines policy allows for this configuration. It would be MOST appropriate for the assessor to advise the organization to:

Options

  • Asegment dual-purpose systems on a hardened network segment with no external access
  • Bassess the risks associated with accepting non-compliance with regulatory requirements
  • Cupdate system implementation procedures to comply with regulations
  • Dreview regulatory requirements and implement new policies on any newly provisioned servers

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    60% (12)
  • D
    25% (5)

Explanation

To avoiding regulatory compliance and hiding your dual purpose systems on a different network segment incurs legal risk / exposure.

Topics

#regulatory compliance#virtualization hardening#policy management#server roles

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice