CAS-003 · Question #966
An organization has hardened its end points m the following ways: - USB ports are disabled except for approved input device IDs (e.g, mouse, keyboard) - A desktop firewall is Mocking all outbound…
The correct answer is B. The end user attached a USB flash drive that has the same device ID as an approved mouse and. The organization's USB policy filters by device ID, not device type. A USB flash drive programmed or relabeled to present the same vendor/product ID as an approved mouse or keyboard would pass the allowlist check and be permitted. All other exfiltration paths are blocked by the…
Question
An organization has hardened its end points m the following ways:
- USB ports are disabled except for approved input device IDs (e.g, mouse, keyboard)
- A desktop firewall is Mocking all outbound network connections, except to approved internal
systems
- A VPN client is the only way to connect to the corporate network remotely and split tunneling is
disabled
- Bluetooth is disabled
- Web browsing from end points is permitted but the traffic is directed through the VPN to the
corporate gateway
- The email client is permitted to connect to the internal server over the VPN and DLP rules
prohibit sending sensitive information to external recipients The organization recently suffered a security breach which a file containing PlI somehow made it from a remote user's laptop to an unauthorized host. Which of the following is the MOST likely for how this happened?
Options
- AThe end user attached the file to an email message and sent it to a personal email account
- BThe end user attached a USB flash drive that has the same device ID as an approved mouse and
- CThe end user connected the computer to a home network and copied the file to an unauthorized
- DThe end user transferred the file to a mobile phone through a wireless connection
- EThe end user uploaded the file to an unauthorized website
How the community answered
(48 responses)- A6% (3)
- B60% (29)
- C10% (5)
- D21% (10)
- E2% (1)
Explanation
The organization's USB policy filters by device ID, not device type. A USB flash drive programmed or relabeled to present the same vendor/product ID as an approved mouse or keyboard would pass the allowlist check and be permitted. All other exfiltration paths are blocked by the stated controls: DLP rules prevent emailing sensitive data to external recipients (A), split tunneling is disabled so the VPN routes all traffic through the corporate gateway - making direct home-network copies impossible (C), Bluetooth is explicitly disabled (D), and web traffic passes through the corporate gateway which would block unauthorized upload sites (E). The device-ID spoofing in option B is the only control gap described.
Topics
Community Discussion
No community discussion yet for this question.