nerdexam
CompTIA

CAS-003 · Question #785

A financial services company wants to migrate its email services from on-premises servers to a cloud-based email solution. The Chief information Security Officer (CISO) must brief board of directors…

The correct answer is A. Data loss prevention. Data Loss Prevention (DLP) is the correct answer. The board's concerns map directly to what DLP addresses: preventing unauthorized access to transaction data, ensuring discretion of client names/account numbers/investment data, and stopping exfiltration of sensitive company…

Technical Integration of Enterprise Security

Question

A financial services company wants to migrate its email services from on-premises servers to a cloud-based email solution. The Chief information Security Officer (CISO) must brief board of directors on the potential security concerns related to this migration. The board is concerned about the following.

  • Transactions being required by unauthorized individual
  • Complete discretion regarding client names, account numbers, and investment information.
  • Malicious attacker using email to distribute malware and ransom ware.
  • Exfiltration of sensitivity company information.

The cloud-based email solution will provide an6-malware, reputation-based scanning, signature- based scanning, and sandboxing. Which of the following is the BEST option to resolve the board's concerns for this email migration?

Options

  • AData loss prevention
  • BEndpoint detection response
  • CSSL VPN
  • DApplication whitelisting

How the community answered

(36 responses)
  • A
    83% (30)
  • B
    6% (2)
  • C
    3% (1)
  • D
    8% (3)

Explanation

Data Loss Prevention (DLP) is the correct answer. The board's concerns map directly to what DLP addresses: preventing unauthorized access to transaction data, ensuring discretion of client names/account numbers/investment data, and stopping exfiltration of sensitive company information. DLP inspects content in motion and at rest, and can block or alert when sensitive financial data (PII, account numbers, investment details) is transmitted outside authorized channels - including via email. The cloud solution already covers the malware/ransomware concern through anti-malware scanning and sandboxing. Endpoint Detection and Response (B) focuses on endpoint threats, not data exfiltration via email. SSL VPN (C) secures remote access tunnels but does not inspect or control what data flows through them. Application whitelisting (D) controls what software runs, not what data is sent.

Topics

#DLP#cloud email security#data exfiltration prevention#anti-malware

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice