SY0-301 · Question #626
Sara, an employee, tethers her smartphone to her work PC to bypass the corporate web security gateway while connected to the LAN. While Sara is out at lunch her PC is compromised via the tethered…
The correct answer is C. Security policy and threat awareness training. The root cause of Sara's behavior is a deliberate policy violation driven by lack of awareness, so security policy enforcement and threat awareness training address the human factor that technical controls alone cannot fully close.
Question
Sara, an employee, tethers her smartphone to her work PC to bypass the corporate web security gateway while connected to the LAN. While Sara is out at lunch her PC is compromised via the tethered connection and corporate data is stolen. Which of the following would BEST prevent this from occurring again?
Options
- ADisable the wireless access and implement strict router ACLs.
- BReduce restrictions on the corporate web security gateway.
- CSecurity policy and threat awareness training.
- DPerform user rights and permissions reviews.
How the community answered
(26 responses)- A4% (1)
- B12% (3)
- C77% (20)
- D8% (2)
Why each option
The root cause of Sara's behavior is a deliberate policy violation driven by lack of awareness, so security policy enforcement and threat awareness training address the human factor that technical controls alone cannot fully close.
Disabling wireless access does not stop USB tethering, which operates over a wired connection between the phone and the PC.
Reducing gateway restrictions weakens security posture and does not prevent the bypass behavior.
Tethering to bypass a corporate gateway is an intentional user action, not a technical misconfiguration. Security awareness training educates employees on acceptable use policies, the legal and organizational risks of circumventing controls, and why such behavior creates the exact data-theft scenario described; without addressing the human element, users will continue finding technical workarounds.
A user rights and permissions review addresses over-provisioned access, not the specific behavior of bypassing security controls via tethering.
Concept tested: Security awareness training to prevent policy bypass
Source: https://www.nist.gov/publications/building-national-computer-security-awareness-and-training-program
Topics
Community Discussion
No community discussion yet for this question.