nerdexam
CompTIA

CAS-003 · Question #52

A security architect is implementing security measures in response to an external audit that found vulnerabilities in the corporate collaboration tool suite. The report identified the lack of any…

The correct answer is A. Issue digital certificates to all users, including owners of group mailboxes, and enable S/MIME. The identified vulnerability is the lack of confidentiality for email correspondence. S/MIME (Secure/Multipurpose Internet Mail Extensions) provides end-to-end encryption and digital signing of emails using certificates. Issuing digital certificates to all users and group…

Technical Integration of Enterprise Security

Question

A security architect is implementing security measures in response to an external audit that found vulnerabilities in the corporate collaboration tool suite. The report identified the lack of any mechanism to provide confidentiality for electronic correspondence between users and between users and group mailboxes. Which of the following controls would BEST mitigate the identified vulnerability?

Options

  • AIssue digital certificates to all users, including owners of group mailboxes, and enable S/MIME
  • BFederate with an existing PKI provider, and reject all non-signed emails
  • CImplement two-factor email authentication, and require users to hash all email messages upon
  • DProvide digital certificates to all systems, and eliminate the user group or shared mailboxes

How the community answered

(42 responses)
  • A
    76% (32)
  • B
    2% (1)
  • C
    7% (3)
  • D
    14% (6)

Explanation

The identified vulnerability is the lack of confidentiality for email correspondence. S/MIME (Secure/Multipurpose Internet Mail Extensions) provides end-to-end encryption and digital signing of emails using certificates. Issuing digital certificates to all users and group mailboxes and enabling S/MIME directly addresses this by encrypting email content in transit and at rest so only the intended recipient can decrypt it. Option B addresses non-signed emails (integrity/authentication) but not confidentiality, and rejecting non-signed emails is disruptive. Option C (hashing) provides integrity, not confidentiality - hashes are one-way and not encryption. Option D eliminates group mailboxes, which is operationally unacceptable and doesn't solve the underlying issue.

Topics

#S/MIME#email encryption#PKI#digital certificates

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice