exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 490 discussion

Actual exam question from CompTIA's CAS-004
Question #: 490
Topic #: 1
[All CAS-004 Questions]

An employee in the accounting department created a potential security incident by emailing an internal spreadsheet to an external email address. The spreadsheet contained thousands of payment card numbers. A security administrator queried the following filter log and filter policy settings:

Outbound filter log information for the email:



Outbound filter policy settings:



Which of the following would best prevent this scenario from reoccurring without causing disruptions to normal business operations?

  • A. Add "Sensitive" data classification tags to all files that include matches to the payment card number format.
  • B. Change the Filter action for Card_Data_Policy from Allow to Quarantine.
  • C. Add the Filter actions Block and Notify to the Confidential_Policy.
  • D. Change the Filter action for all Attachment_Policy from Allow to Block.
  • E. Change the Filter action for Personal_Email_Policy from Quarantine to Block.
  • F. Configure the Monitor action to send automated alerts to the sender's immediate supervisor.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
3 weeks, 2 days ago
Selected Answer: B
B. Change the Filter action for Card_Data_Policy from Allow to Quarantine: This would be the most effective approach to prevent future incidents like this. Changing the action from Allow to Quarantine would ensure that emails containing payment card information (based on the Card_Data_Policy filter) are flagged and stopped before being sent out, without disrupting normal operations. The email could still be reviewed later, but it would not be allowed to reach the external recipient immediately. This change targets the root cause, which is the accidental or intentional emailing of sensitive data. So, this is the most effective solution to prevent future incidents of sensitive data being emailed without disrupting normal business operations. This ensures that emails containing sensitive payment card data are stopped and reviewed before being sent externally.
upvoted 1 times
...
EAlonso
5 months, 4 weeks ago
Selected Answer: B
Well, no other more than B.
upvoted 3 times
...
EAlonso
5 months, 4 weeks ago
C. It could look disruptive, but comparing Sensitive_Policy actions are higher than Confidential_Policy, and credit card information is Confidential in any context. https://www.recordpoint.com/blog/a-guide-to-data-classification-confidential-vs-sensitive-vs-public-information https://www.recordpoint.com/blog/a-guide-to-data-classification-confidential-vs-sensitive-vs-public-information
upvoted 1 times
...
23169fd
5 months, 4 weeks ago
Selected Answer: B
Quarantining emails containing payment card data would prevent them from being sent without review, which is effective but could disrupt normal operations by delaying email delivery.
upvoted 3 times
...
armid
6 months, 1 week ago
Selected Answer: B
my previous answer is incorrect
upvoted 2 times
...
armid
6 months, 1 week ago
Selected Answer: A
If this is single answer question i would say A. Sensitive policy is already in block mode but not included in the filter log. We are modifying the data sensitivity labels and not the existing policies, which sounds in line with "least disruptions" to me. B offers itself, but the clause "without disruptions to normal business operations" makes me sway towards A. Plus we are judging the policy just by its name. If two answer question then A+B C doesn't apply because it could be disruptive D would be super disruptive E doesn't qualify as nowhere in the question is stated that the external mail is personal F doesn't qualify as it is just monitor and action would be taken too late
upvoted 1 times
armid
6 months, 1 week ago
oh i am sorry disregard, the sensitive is not in the filter log, so defintely not A Must be B then
upvoted 1 times
...
...
isaphiltrick
6 months, 1 week ago
Is this a one or two answer question? Almost all previous questions with 6 or more questions were multiple answers. If one answer, I choose B. Change the Filter action for Card_Data_Policy from Allow to Quarantine. If two-answers are required, I choose B. Change the Filter action for Card_Data_Policy from Allow to Quarantine and D. Change the Filter action for all Attachment_Policy from Allow to Block.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago