GSLC · Question #464
You are responsible for security on your network. One particular concern is the theft of sensitive data. You want to make sure that end users do not (purposefully or accidentally) take data off the…
The correct answer is A. Cell Phones B. Individual scanners C. USB Drives D. Individual printers. Preventing data exfiltration requires addressing all physical and digital endpoints through which data can leave the premises, including portable devices, printing, and scanning.
Question
You are responsible for security on your network. One particular concern is the theft of sensitive data. You want to make sure that end users do not (purposefully or accidentally) take data off the premises. Which of the following should you be concerned about? Each correct answer represents a complete solution. Choose all that apply.
Options
- ACell Phones
- BIndividual scanners
- CUSB Drives
- DIndividual printers
How the community answered
(43 responses)- A100% (43)
Why each option
Preventing data exfiltration requires addressing all physical and digital endpoints through which data can leave the premises, including portable devices, printing, and scanning.
Cell phones can store large amounts of data, photograph documents, and transmit data wirelessly, making them a significant data exfiltration vector.
Individual scanners can digitize physical documents and save or transmit that data outside the organization, representing a physical-to-digital exfiltration path.
USB drives are one of the most common data exfiltration tools because they are small, high-capacity, and can be used to copy files directly from workstations without network monitoring.
Individual printers allow users to produce physical copies of sensitive digital data that can then be physically removed from the premises, bypassing digital data loss prevention controls.
Concept tested: Data Loss Prevention - physical exfiltration vectors
Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-data-exfiltration
Topics
Community Discussion
No community discussion yet for this question.