GCIH · Question #158
The IT administrator wants to implement a stronger security policy. What are the four most
The correct answer is A. Providing secure communications between the overseas office and the headquarters. C. Protecting employee data on portable computers. E. Ensuring secure authentication. F. Preventing unauthorized network access. The four highest-priority security policy areas cover encrypted remote communications, portable device data protection, secure authentication, and unauthorized access prevention.
Question
The IT administrator wants to implement a stronger security policy. What are the four most
Options
- AProviding secure communications between the overseas office and the headquarters.
- BImplementing Certificate services on Texas office.
- CProtecting employee data on portable computers.
- DProviding two-factor authentication.
- EEnsuring secure authentication.
- FPreventing unauthorized network access.
- GProviding secure communications between Washington and the headquarters office.
- HPreventing denial-of-service attacks.
How the community answered
(23 responses)- A74% (17)
- D4% (1)
- G9% (2)
- H13% (3)
Why each option
The four highest-priority security policy areas cover encrypted remote communications, portable device data protection, secure authentication, and unauthorized access prevention.
Securing communications between remote offices and headquarters protects sensitive data traversing untrusted public networks, representing a fundamental perimeter security requirement.
Implementing Certificate Services on one specific office is a narrow infrastructure task, not a broad organizational security policy priority.
Portable computers present a direct physical theft risk, making data-at-rest encryption and protection a critical policy priority that addresses a high-probability loss scenario.
Two-factor authentication is a specific implementation mechanism that falls under the broader policy goal of ensuring secure authentication covered by choice E.
Ensuring secure authentication is foundational to all access control - without it, any other security control can be bypassed by an attacker who gains unauthorized identity.
Preventing unauthorized network access enforces the principle of least privilege at the network boundary and is a core security policy requirement for any organization.
Securing communications between one specific branch and headquarters is a subset of the broader remote office communication security addressed by choice A.
Preventing denial-of-service attacks, while valid, is a reactive and lower-priority hardening concern compared to the foundational access control and authentication priorities.
Concept tested: Security policy priority selection and risk-based planning
Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-security-policy
Topics
Community Discussion
No community discussion yet for this question.