CAS-003 · Question #839
A security engineer needs to implement controls that will prevent the theft of data by insiders who have valid credentials. Recent incidents were carried out with mobile and wearable devices that…
The correct answer is A. Limit the ability to transfer data via Bluetooth connections. When mobile and wearable devices are used as insider data exfiltration vectors and USB is already controlled, limiting Bluetooth connections closes the next most accessible wireless data transfer channel.
Question
A security engineer needs to implement controls that will prevent the theft of data by insiders who have valid credentials. Recent incidents were carried out with mobile and wearable devices that were used as transfer vectors. In response, USB data transfers are now tightly controlled and require executive authorization. Which of the following controls will further reduce the likelihood of another data theft?
Options
- ALimit the ability to transfer data via Bluetooth connections.
- BMove the enterprise to a BYOD or COPE policy.
- CDeploy strong transit encryption across the enterprise.
- DImplement time-based restrictions on data transfers.
How the community answered
(45 responses)- A82% (37)
- B7% (3)
- C9% (4)
- D2% (1)
Why each option
When mobile and wearable devices are used as insider data exfiltration vectors and USB is already controlled, limiting Bluetooth connections closes the next most accessible wireless data transfer channel.
Mobile and wearable devices natively support Bluetooth as a short-range wireless protocol capable of transferring files and data independently of USB or network controls. Because Bluetooth provides a direct, difficult-to-monitor data path between a corporate device and a personal receiver, restricting Bluetooth data transfers removes a primary alternative exfiltration channel that insiders with valid credentials could exploit even with USB controls in place.
Adopting a BYOD or COPE policy changes device ownership and management models but does not technically prevent authorized insiders from using Bluetooth or other wireless protocols on those devices to transfer data.
Strong transit encryption protects data from interception by unauthorized third parties during transmission but does not prevent an authorized insider from deliberately copying data to a personal mobile or wearable device via a local wireless channel.
Time-based transfer restrictions limit the window in which data transfers can occur but do not block the use of Bluetooth or other wireless protocols on mobile and wearable devices during those permitted windows.
Concept tested: Wireless protocol control for insider threat mitigation
Source: https://csrc.nist.gov/publications/detail/sp/800-121/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.