CAS-003 · Question #742
While traveling to another state, the Chief Financial (CFO) forgot to submit payroll for the company. The CFO quickly gained to the corporate through the high-speed wireless network provided by the…
The correct answer is A. The security manager did not enforce automate VPN connection. The CFO connected to the corporate network over an untrusted hotel WiFi network without a VPN, exposing the session to interception or man-in-the-middle attack. A policy enforcing automatic VPN connection whenever a device is on an untrusted network would have encrypted all…
Question
While traveling to another state, the Chief Financial (CFO) forgot to submit payroll for the company. The CFO quickly gained to the corporate through the high-speed wireless network provided by the hotel and completed the desk. Upon returning from the business trip, the CFO was told no one received their weekly pay due to a malware on attack on the system. Which of the following is the MOST likely of the security breach?
Options
- AThe security manager did not enforce automate VPN connection.
- BThe company's server did not have endpoint security enabled.
- CThe hotel and did require a wireless password to authenticate.
- DThe laptop did not have the host-based firewall properly configured.
How the community answered
(35 responses)- A74% (26)
- B9% (3)
- C3% (1)
- D14% (5)
Explanation
The CFO connected to the corporate network over an untrusted hotel WiFi network without a VPN, exposing the session to interception or man-in-the-middle attack. A policy enforcing automatic VPN connection whenever a device is on an untrusted network would have encrypted all traffic, preventing attackers on the hotel network from injecting malware or stealing credentials. Option C (hotel not requiring a WiFi password) is a contributing risk factor, but even password-protected hotel networks are untrusted - a mandatory VPN is the correct mitigation. Option B (no endpoint security on the server) and Option D (firewall misconfiguration) are less direct causes compared to the clearly unprotected public network connection.
Topics
Community Discussion
No community discussion yet for this question.