CAS-003 · Question #454
A security assessor is working with an organization to review the policies and procedures associated with managing the organization's virtual infrastructure. During a review of the virtual…
The correct answer is C. update system implementation procedures to comply with regulations. To avoiding regulatory compliance and hiding your dual purpose systems on a different network segment incurs legal risk / exposure.
Question
A security assessor is working with an organization to review the policies and procedures associated with managing the organization's virtual infrastructure. During a review of the virtual environment, the assessor determines the organization is using servers to provide more than one primary function, which violates a regulatory requirement. The assessor reviews hardening guides and determines policy allows for this configuration. It would be MOST appropriate for the assessor to advise the organization to:
Options
- Asegment dual-purpose systems on a hardened network segment with no external access
- Bassess the risks associated with accepting non-compliance with regulatory requirements
- Cupdate system implementation procedures to comply with regulations
- Dreview regulatory requirements and implement new policies on any newly provisioned servers
How the community answered
(20 responses)- A5% (1)
- B10% (2)
- C60% (12)
- D25% (5)
Explanation
To avoiding regulatory compliance and hiding your dual purpose systems on a different network segment incurs legal risk / exposure.
Topics
Community Discussion
No community discussion yet for this question.