CAS-003 · Question #558
An investigation showed a worm was introduced from an engineer's laptop. It was determined the company does not provide engineers with company-owned laptops, which would be subject to a company…
The correct answer is A. Deploy HIDS on all engineer-provided laptops, and put a new router in the management network. Because the company does not supply engineers with corporate laptops, it has limited control over personally owned devices. Deploying a Host-based Intrusion Detection System (HIDS) on all engineer-provided laptops-combined with placing a new router in the management network to…
Question
An investigation showed a worm was introduced from an engineer's laptop. It was determined the company does not provide engineers with company-owned laptops, which would be subject to a company policy and technical controls. Which of the following would be the MOST secure control implement?
Options
- ADeploy HIDS on all engineer-provided laptops, and put a new router in the management network.
- BImplement role-based group policies on the management network for client access.
- CUtilize a jump box that is only allowed to connect to client from the management network.
- DDeploy a company-wide approved engineering workstation for management access.
How the community answered
(32 responses)- A72% (23)
- B16% (5)
- C9% (3)
- D3% (1)
Explanation
Because the company does not supply engineers with corporate laptops, it has limited control over personally owned devices. Deploying a Host-based Intrusion Detection System (HIDS) on all engineer-provided laptops-combined with placing a new router in the management network to add segmentation-provides the best available detective and preventive controls given the BYOD constraint. HIDS monitors host-level activity for malware or policy violations, and the new router enforces network boundaries. Option C (jump box) is a strong control but only addresses network-level access, not host-level threats on the endpoint itself. Option D would be the most secure architecturally but contradicts the stated company policy of not issuing company-owned laptops.
Topics
Community Discussion
No community discussion yet for this question.