ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 426 - CAS-004 discussion

Report
Export

A security officer is requiring all personnel working on a special project to obtain a security clearance requisite with the level of all information being accessed Data on this network must be protected at the same level of each clearance holder The need to know must be vended by the data owner Which of the following should the security officer do to meet these requirements?

A.
Create a rule lo authorize personnel only from certain IPs to access the files
Answers
A.
Create a rule lo authorize personnel only from certain IPs to access the files
B.
Assign labels to the files and require formal access authorization
Answers
B.
Assign labels to the files and require formal access authorization
C.
Assign attributes to each file and allow authorized users to share the files
Answers
C.
Assign attributes to each file and allow authorized users to share the files
D.
Assign roles to users and authorize access to files based on the roles
Answers
D.
Assign roles to users and authorize access to files based on the roles
Suggested answer: B

Explanation:

Labeling files and requiring formal access authorization is a method that aligns with the principle of least privilege and the need-to-know basis. By assigning labels to files based on their sensitivity and requiring formal access approval from the data owner, the security officer can ensure that only personnel with the necessary clearance and a legitimate need to access the information can do so. This approach helps in maintaining data confidentiality and integrity in line with the project's security requirements.

asked 02/10/2024
Randy Kana
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first