SY0-301 · Question #850
Sara, the Chief Information Officer (CIO), has tasked the IT department with redesigning the network to rely less on perimeter firewalls, to implement a standard operating environment for client…
The correct answer is B. Data exfiltration. The CIO's initiative to control endpoints and eliminate personal devices reflects the primary concern that unmanaged devices create pathways for sensitive data to leave the organization.
Question
Sara, the Chief Information Officer (CIO), has tasked the IT department with redesigning the network to rely less on perimeter firewalls, to implement a standard operating environment for client devices, and to disallow personally managed devices on the network. Which of the following is Sara's GREATEST concern?
Options
- AMalicious internal attacks
- BData exfiltration
- CAudit findings
- DIncident response
How the community answered
(53 responses)- A8% (4)
- B79% (42)
- C2% (1)
- D11% (6)
Why each option
The CIO's initiative to control endpoints and eliminate personal devices reflects the primary concern that unmanaged devices create pathways for sensitive data to leave the organization.
Malicious internal attacks are addressed by other controls such as access monitoring; the described measures - device standardization and banning personal devices - are more targeted at data pathway control than internal threat detection.
Data exfiltration is the greatest concern because personally managed and uncontrolled devices can bypass corporate data governance controls, allowing sensitive information to be copied, transmitted, or leaked externally. The shift away from perimeter-only security toward endpoint standardization directly addresses the risk of data leaving through unmanaged, untrusted devices.
Audit findings represent a compliance outcome rather than a security risk that would motivate a fundamental network architecture redesign.
Incident response is a reactive process and does not drive the proactive architectural decisions described, which focus on preventing data exposure before an incident occurs.
Concept tested: Data exfiltration risk and endpoint control strategy
Source: https://csrc.nist.gov/publications/detail/sp/800-171/rev-3/final
Topics
Community Discussion
No community discussion yet for this question.