nerdexam
CompTIA

SY0-301 · Question #626

Sara, an employee, tethers her smartphone to her work PC to bypass the corporate web security gateway while connected to the LAN. While Sara is out at lunch her PC is compromised via the tethered…

The correct answer is C. Security policy and threat awareness training. The root cause of Sara's behavior is a deliberate policy violation driven by lack of awareness, so security policy enforcement and threat awareness training address the human factor that technical controls alone cannot fully close.

Security program management and oversight

Question

Sara, an employee, tethers her smartphone to her work PC to bypass the corporate web security gateway while connected to the LAN. While Sara is out at lunch her PC is compromised via the tethered connection and corporate data is stolen. Which of the following would BEST prevent this from occurring again?

Options

  • ADisable the wireless access and implement strict router ACLs.
  • BReduce restrictions on the corporate web security gateway.
  • CSecurity policy and threat awareness training.
  • DPerform user rights and permissions reviews.

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    12% (3)
  • C
    77% (20)
  • D
    8% (2)

Why each option

The root cause of Sara's behavior is a deliberate policy violation driven by lack of awareness, so security policy enforcement and threat awareness training address the human factor that technical controls alone cannot fully close.

ADisable the wireless access and implement strict router ACLs.

Disabling wireless access does not stop USB tethering, which operates over a wired connection between the phone and the PC.

BReduce restrictions on the corporate web security gateway.

Reducing gateway restrictions weakens security posture and does not prevent the bypass behavior.

CSecurity policy and threat awareness training.Correct

Tethering to bypass a corporate gateway is an intentional user action, not a technical misconfiguration. Security awareness training educates employees on acceptable use policies, the legal and organizational risks of circumventing controls, and why such behavior creates the exact data-theft scenario described; without addressing the human element, users will continue finding technical workarounds.

DPerform user rights and permissions reviews.

A user rights and permissions review addresses over-provisioned access, not the specific behavior of bypassing security controls via tethering.

Concept tested: Security awareness training to prevent policy bypass

Source: https://www.nist.gov/publications/building-national-computer-security-awareness-and-training-program

Topics

#security policy#insider threat#mobile tethering#security awareness training

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice