nerdexam
CompTIA

CAS-003 · Question #60

An organization has decided to reduce labor costs by outsourcing back office processing of credit applications to a provider located in another country. Data sovereignty and privacy concerns raised…

The correct answer is C. Disable cross session cut and paste E. User access audit reviews F. Source IP whitelisting. Data sovereignty is a legal concern where the data is governed by the laws of the country in which the data resides. In this scenario the company does not want the data to fall under the law of the country of the organization to whom back office process has be outsourced to…

Enterprise Security Architecture

Question

An organization has decided to reduce labor costs by outsourcing back office processing of credit applications to a provider located in another country. Data sovereignty and privacy concerns raised by the security team resulted in the third-party provider only accessing and processing the data via remote desktop sessions. To facilitate communications and improve productivity, staff at the third party has been provided with corporate email accounts that are only accessible via the remote desktop sessions. Email forwarding is blocked and staff at the third party can only communicate with staff within the organization. Which of the following additional controls should be implemented to prevent data loss? (Select THREE).

Options

  • AImplement hashing of data in transit
  • BSession recording and capture
  • CDisable cross session cut and paste
  • DMonitor approved credit accounts
  • EUser access audit reviews
  • FSource IP whitelisting

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    24% (6)
  • C
    60% (15)
  • D
    12% (3)

Explanation

Data sovereignty is a legal concern where the data is governed by the laws of the country in which the data resides. In this scenario the company does not want the data to fall under the law of the country of the organization to whom back office process has be outsourced to. Therefore we must ensure that data can only be accessed on local servers and no copies are held on computers of the outsource partner. It is important therefore to prevent cut and paste operations. Privacy concerns can be addressed by ensuring the unauthorized users do not have access to the data. This can be accomplished though user access auditing, which needs to be reviewed on an ongoing basis; and source IP whitelisting, which is a list of IP addresses that are explicitly allowed access to the system.

Topics

#third-party risk#remote desktop security#session security#data exfiltration prevention

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice