nerdexam
CompTIA

CAS-003 · Question #478

An organization is reviewing endpoint security solutions. In evaluating products, the organization has the following requirements: 1. Support server, laptop, and desktop infrastructure 2. Due to…

The correct answer is C. Endpoint detect and respond D. Rights management. The four requirements map directly to two specific capabilities. Endpoint Detection and Response (EDR) satisfies requirements 1 and 2: it runs on servers, laptops, and desktops, and provides active (automated) protection without requiring constant manual intervention from a…

Enterprise Security Architecture

Question

An organization is reviewing endpoint security solutions. In evaluating products, the organization has the following requirements: 1. Support server, laptop, and desktop infrastructure 2. Due to limited security resources, implement active protection capabilities 3. Provide users with the ability to self-service classify information and apply policies 4. Protect data-at-rest and data-in-use Which of the following endpoint capabilities would BEST meet the above requirements? (Select two.)

Options

  • AData loss prevention
  • BApplication whitelisting
  • CEndpoint detect and respond
  • DRights management
  • ELog monitoring
  • FAntivirus

How the community answered

(57 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    81% (46)
  • E
    11% (6)
  • F
    2% (1)

Explanation

The four requirements map directly to two specific capabilities. Endpoint Detection and Response (EDR) satisfies requirements 1 and 2: it runs on servers, laptops, and desktops, and provides active (automated) protection without requiring constant manual intervention from a small security team. Rights Management (IRM/DRM) satisfies requirements 3 and 4: it empowers users to self-classify and label documents and apply usage policies themselves, and it protects data both at rest (files are encrypted) and in use (policies are enforced even when a file is open or shared). DLP (A) protects data in transit but does not give users a self-service classification workflow. Application whitelisting (B) controls software execution, not data. Log monitoring (E) is passive, not protective. Antivirus (F) is reactive and does not address data classification or protection policies.

Topics

#endpoint security#DLP#EDR#rights management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice