nerdexam
CompTIA

CAS-003 · Question #582

After an employee was terminated, the company discovered the employee still had access to emails and attached content that should have been destroyed during the off-boarding. The employee's laptop…

The correct answer is C. Restrict access to company systems to expected times of day and geographic locations. Time- and location-based access restrictions would automatically block access attempts outside the employee's normal usage profile, closing the gap between termination notification and full account disablement.

Enterprise Security Operations

Question

After an employee was terminated, the company discovered the employee still had access to emails and attached content that should have been destroyed during the off-boarding. The employee's laptop and cell phone were confiscated and accounts were disabled promptly. Forensic investigation suggests the company's DLP was effective, and the content in QUESTION 5was not sent outside of work or transferred to removable media. Personality owned devices are not permitted to access company systems or information. Which of the following would be the MOST efficient control to prevent this from occurring in the future?

Options

  • AInstall application whitelist on mobile devices.
  • BDisallow side loading of applications on mobile devices.
  • CRestrict access to company systems to expected times of day and geographic locations.
  • DPrevent backup of mobile devices to personally owned computers.
  • EPerform unannounced insider threat testing on high-risk employees.

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    11% (5)
  • C
    57% (25)
  • D
    2% (1)
  • E
    23% (10)

Why each option

Time- and location-based access restrictions would automatically block access attempts outside the employee's normal usage profile, closing the gap between termination notification and full account disablement.

AInstall application whitelist on mobile devices.

Application whitelisting controls which executables can run on a device, but does not restrict authenticated access to email content once valid credentials remain active.

BDisallow side loading of applications on mobile devices.

Disabling sideloading prevents installation of unauthorized apps, which is unrelated to the access control gap that allowed continued email access during off-boarding.

CRestrict access to company systems to expected times of day and geographic locations.Correct

Restricting access to expected times of day and geographic locations creates a conditional access policy that automatically denies authentication from unexpected contexts - such as off-hours or off-site locations - covering the window between a termination decision and manual account disablement. This control is efficient because it is automated, always enforced, and does not depend on the speed of the HR or IT off-boarding workflow.

DPrevent backup of mobile devices to personally owned computers.

Preventing backup to personally owned computers is already addressed by the existing effective DLP controls and the no-personal-device policy stated in the scenario.

EPerform unannounced insider threat testing on high-risk employees.

Unannounced insider threat testing is a detective and deterrent control, not a preventive technical mechanism, and would not have blocked residual access after termination.

Concept tested: Conditional access controls for employee off-boarding

Source: https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview

Topics

#off-boarding controls#access management#insider threat#geographic restrictions

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice