CAS-003 · Question #582
After an employee was terminated, the company discovered the employee still had access to emails and attached content that should have been destroyed during the off-boarding. The employee's laptop…
The correct answer is C. Restrict access to company systems to expected times of day and geographic locations. Time- and location-based access restrictions would automatically block access attempts outside the employee's normal usage profile, closing the gap between termination notification and full account disablement.
Question
After an employee was terminated, the company discovered the employee still had access to emails and attached content that should have been destroyed during the off-boarding. The employee's laptop and cell phone were confiscated and accounts were disabled promptly. Forensic investigation suggests the company's DLP was effective, and the content in QUESTION 5was not sent outside of work or transferred to removable media. Personality owned devices are not permitted to access company systems or information. Which of the following would be the MOST efficient control to prevent this from occurring in the future?
Options
- AInstall application whitelist on mobile devices.
- BDisallow side loading of applications on mobile devices.
- CRestrict access to company systems to expected times of day and geographic locations.
- DPrevent backup of mobile devices to personally owned computers.
- EPerform unannounced insider threat testing on high-risk employees.
How the community answered
(44 responses)- A7% (3)
- B11% (5)
- C57% (25)
- D2% (1)
- E23% (10)
Why each option
Time- and location-based access restrictions would automatically block access attempts outside the employee's normal usage profile, closing the gap between termination notification and full account disablement.
Application whitelisting controls which executables can run on a device, but does not restrict authenticated access to email content once valid credentials remain active.
Disabling sideloading prevents installation of unauthorized apps, which is unrelated to the access control gap that allowed continued email access during off-boarding.
Restricting access to expected times of day and geographic locations creates a conditional access policy that automatically denies authentication from unexpected contexts - such as off-hours or off-site locations - covering the window between a termination decision and manual account disablement. This control is efficient because it is automated, always enforced, and does not depend on the speed of the HR or IT off-boarding workflow.
Preventing backup to personally owned computers is already addressed by the existing effective DLP controls and the no-personal-device policy stated in the scenario.
Unannounced insider threat testing is a detective and deterrent control, not a preventive technical mechanism, and would not have blocked residual access after termination.
Concept tested: Conditional access controls for employee off-boarding
Source: https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview
Topics
Community Discussion
No community discussion yet for this question.