CAS-003 · Question #754
The government is concerned with remote military missions being negatively impacted by the use of technology that may fail to protect operational security. To remediate this concern, a number of…
The correct answer is B. Family members posting geotagged images on social media that were received via email from. Option B is correct. The greatest OPSEC (Operational Security) residual concern is family members posting geotagged photos on social media that originated from soldiers via the secured email channel. Here's why: the end-to-end encryption protects the email in transit, but once…
Question
The government is concerned with remote military missions being negatively impacted by the use of technology that may fail to protect operational security. To remediate this concern, a number of solutions have been implemented, including the following:
- End-to-end encryption of all inbound and outbound communication, including personal email
and chat sessions that allow solders to securely communicate with families
- Layer 7 inspection and TCP/UDP port restriction, including firewall rules to only allow TCP port
80 and 443 and approved applications
- A host-based whitelist of approved websites and applications that only allow mission-related
tools and sites
- The use of satellite communication to include multiple proxy servers to scramble the source IP
address Which of the following is of MOST concern in this scenario?
Options
- AThe unsecure port 80 being used for general web traffic
- BFamily members posting geotagged images on social media that were received via email from
- CThe effect of communication latency that may negatively impact real-time communication with
- DThe use of centrally managed military network and computers by solders when communicating
How the community answered
(27 responses)- A30% (8)
- B52% (14)
- C4% (1)
- D15% (4)
Explanation
Option B is correct. The greatest OPSEC (Operational Security) residual concern is family members posting geotagged photos on social media that originated from soldiers via the secured email channel. Here's why: the end-to-end encryption protects the email in transit, but once a family member receives a photo and posts it to a public social media platform, the embedded GPS metadata (geotag) in the image can reveal the soldier's precise location or the mission area. No technical control in the listed solutions prevents this downstream action by a third party. Option A (port 80) is a concern but is partially mitigated by the existing firewall rules. Option C is an operational impact issue, not a security vulnerability. Option D (using military-managed computers) is actually a security control, not a threat.
Topics
Community Discussion
No community discussion yet for this question.