nerdexam
CompTIA

CAS-003 · Question #736

A company recently deployed an agent-based DLP solution to all laptop in the environment. The DLP solution is configured to restrict the following: - USB ports - FTP connections - Access to…

The correct answer is A. Application whitelisting for all company-owned devices. The DLP solution blocks many known exfiltration channels (USB, FTP, cloud storage, email attachments, local C: drive), yet data was still stolen from the research fileshare. This strongly suggests an unauthorized application - such as a custom exfiltration tool, rogue sync…

Enterprise Security Operations

Question

A company recently deployed an agent-based DLP solution to all laptop in the environment. The DLP solution is configured to restrict the following:

  • USB ports
  • FTP connections
  • Access to cloud-based storage sites
  • Outgoing email attachments
  • Saving data on the local C: drive

Despite these restrictions, highly confidential data was from a secure fileshare in the research department. Which of the following should the security team implement FIRST?

Options

  • AApplication whitelisting for all company-owned devices
  • BA secure VDI environment for research department employees
  • CNIDS/NIPS on the network segment used by the research department
  • DBluetooth restriction on all laptops

How the community answered

(35 responses)
  • A
    69% (24)
  • B
    9% (3)
  • C
    17% (6)
  • D
    6% (2)

Explanation

The DLP solution blocks many known exfiltration channels (USB, FTP, cloud storage, email attachments, local C: drive), yet data was still stolen from the research fileshare. This strongly suggests an unauthorized application - such as a custom exfiltration tool, rogue sync client, or Bluetooth application - was used to bypass the agent-based DLP controls. Application whitelisting prevents any non-approved executable from running, closing this gap. A VDI environment (B) and NIDS/NIPS (C) are useful secondary controls but don't stop a rogue process already running on the endpoint. Bluetooth restriction (D) is one specific channel and should be addressed, but whitelisting covers all unauthorized software broadly.

Topics

#DLP#application whitelisting#data exfiltration#insider threat

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice