nerdexam
GIAC

GCIH · Question #158

The IT administrator wants to implement a stronger security policy. What are the four most

The correct answer is A. Providing secure communications between the overseas office and the headquarters. C. Protecting employee data on portable computers. E. Ensuring secure authentication. F. Preventing unauthorized network access. The four highest-priority security policy areas cover encrypted remote communications, portable device data protection, secure authentication, and unauthorized access prevention.

Incident Response & Cyber Kill Chain

Question

The IT administrator wants to implement a stronger security policy. What are the four most

Options

  • AProviding secure communications between the overseas office and the headquarters.
  • BImplementing Certificate services on Texas office.
  • CProtecting employee data on portable computers.
  • DProviding two-factor authentication.
  • EEnsuring secure authentication.
  • FPreventing unauthorized network access.
  • GProviding secure communications between Washington and the headquarters office.
  • HPreventing denial-of-service attacks.

How the community answered

(23 responses)
  • A
    74% (17)
  • D
    4% (1)
  • G
    9% (2)
  • H
    13% (3)

Why each option

The four highest-priority security policy areas cover encrypted remote communications, portable device data protection, secure authentication, and unauthorized access prevention.

AProviding secure communications between the overseas office and the headquarters.Correct

Securing communications between remote offices and headquarters protects sensitive data traversing untrusted public networks, representing a fundamental perimeter security requirement.

BImplementing Certificate services on Texas office.

Implementing Certificate Services on one specific office is a narrow infrastructure task, not a broad organizational security policy priority.

CProtecting employee data on portable computers.Correct

Portable computers present a direct physical theft risk, making data-at-rest encryption and protection a critical policy priority that addresses a high-probability loss scenario.

DProviding two-factor authentication.

Two-factor authentication is a specific implementation mechanism that falls under the broader policy goal of ensuring secure authentication covered by choice E.

EEnsuring secure authentication.Correct

Ensuring secure authentication is foundational to all access control - without it, any other security control can be bypassed by an attacker who gains unauthorized identity.

FPreventing unauthorized network access.Correct

Preventing unauthorized network access enforces the principle of least privilege at the network boundary and is a core security policy requirement for any organization.

GProviding secure communications between Washington and the headquarters office.

Securing communications between one specific branch and headquarters is a subset of the broader remote office communication security addressed by choice A.

HPreventing denial-of-service attacks.

Preventing denial-of-service attacks, while valid, is a reactive and lower-priority hardening concern compared to the foundational access control and authentication priorities.

Concept tested: Security policy priority selection and risk-based planning

Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-security-policy

Topics

#security policy#authentication#network access control#data protection

Community Discussion

No community discussion yet for this question.

Full GCIH Practice