nerdexam
CompTIA

CAS-003 · Question #886

The Chief Information Officer (CIO) asks the systems administrator to improve email security at the company based on the following requirements: 1. Do not use two-factor authentication. 2. Protect…

The correct answer is A. SPML D. SSL. Based on the listed requirements, the correct combination is S/MIME and TLS. S/MIME (Secure/Multipurpose Internet Mail Extensions) satisfies the majority of requirements: it encrypts mailbox contents, enables digital signatures, protects against email spoofing, uses X.509…

Technical Integration of Enterprise Security

Question

The Chief Information Officer (CIO) asks the systems administrator to improve email security at the company based on the following requirements: 1. Do not use two-factor authentication. 2. Protect the contents of a user's mailbox. 3. Be able to sign emails digitally. 4. Protect internal users from spoofing. 5. Secure communications in transit. 6. Use a hierarchically validated certifier for key exchange. 7. Do not use additional plug-in. 8. Have minimal impact to the end-user experience. Which of the following, when used together, should the systems administrator implement to BEST meet the objectives? (Select TWO).

Options

  • ASPML
  • BS/MIME
  • CSIP
  • DSSL
  • ETLS
  • FPGP

How the community answered

(63 responses)
  • A
    79% (50)
  • B
    3% (2)
  • C
    10% (6)
  • E
    2% (1)
  • F
    6% (4)

Explanation

Based on the listed requirements, the correct combination is S/MIME and TLS. S/MIME (Secure/Multipurpose Internet Mail Extensions) satisfies the majority of requirements: it encrypts mailbox contents, enables digital signatures, protects against email spoofing, uses X.509 certificates issued by a hierarchical PKI (meeting the 'hierarchically validated certifier' requirement), and is built natively into enterprise email clients (no additional plug-ins, minimal user impact). TLS secures email communications in transit between mail servers, is transparent to end users, and requires no additional software. PGP (F) is technically capable but relies on a web-of-trust model, not a hierarchical certifier, and typically requires a plug-in. The stated correct answer of A (SPML - a provisioning markup language) is almost certainly a labeling error in the question source; SPML is unrelated to email security.

Topics

#S/MIME#email security#TLS#digital signatures

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice