exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 382 discussion

Actual exam question from CompTIA's CS0-002
Question #: 382
Topic #: 1
[All CS0-002 Questions]

A Chief Information Security Officer is concerned that contract developers may be able to steal the code used to design the company’s latest application since they are able to pull code from a cloud-based repository directly to laptops that are not owned by the company. Which of the following solutions would best protect the company code from being stolen?

  • A. MDM
  • B. SCA
  • C. CASB
  • D. VDI
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
grelaman
1 year, 7 months ago
Selected Answer: D
VDI solution could be a strong measure to prevent code theft in the scenario described. VDI allows users, including developers, to access a virtualized desktop environment hosted on a server rather than working on a local machine. Beneifts: 1. Controlled Environment 2 Restricted Access 3 Data Isolation (The code and other sensitive data remain within the virtual environment) 4 Centralized Management
upvoted 1 times
...
sirpetey
1 year, 7 months ago
Selected Answer: C
I have no clue how these people getting VDI... CASB will protect the data
upvoted 2 times
...
kumax
1 year, 8 months ago
Selected Answer: C
ChatGPT: To protect the company code from being stolen when contract developers are working with code repositories on laptops not owned by the company, a Cloud Access Security Broker (CASB) is the more suitable solution.
upvoted 1 times
Chilaqui1es
1 year, 8 months ago
ChatGPT is not always accurate
upvoted 3 times
...
...
Bubu3k
1 year, 10 months ago
Selected Answer: D
The "contract developers" need to be able to do pulls in order to work on the code. Blocking access to the code completely is not an option. It's a common practice for employers/contractors that don't receive a laptop, to be given access to a VDI. This way the developers are able to work on the code, but downloading the code from the VDI to their laptop can be blocked in a few ways. I would go with D.....but god knows what Comptia and their weird questions are expecting for an answer...
upvoted 1 times
...
Rori791
1 year, 11 months ago
Selected Answer: C
I can see why some selected VDI because it can be used to access a virtual desktop environment from their personal devices, rather than directly accessing the company's network. The thing is VDI only focuses on providing secure access to company applications and data, but does not provide specific security controls for cloud-based repositories. CASB provides security controls specifically designed to protect cloud-based repositories, including access control, data loss prevention (DLP), and visibility into user activity and data usage. So it can help prevent confidential data from leaving company-controlled systems and protect the integrity of the data, even if it is accessed from a personal device outside the company's network.
upvoted 2 times
Rori791
1 year, 11 months ago
+ Key word is “cloud-based repository” so the data in question is stored in a cloud-based repository, CASB would be the most appropriate solution to protect the company code from being stolen.
upvoted 2 times
...
...
Dany_Suarez
2 years ago
Selected Answer: C
CompTIA gide says: CASBs provide the organization with great visibility into how clients and other network nodes are using cloud services. They also enable the organization to apply techniques like access control and data loss/leak prevention (DLP) to ensure that sensitive data is not at risk of compromise as it traverses the Internet, bound for disparate networks.
upvoted 2 times
...
tutita
2 years ago
Selected Answer: C
I don't understand how VDI will help with exfiltrating data in this case? if they are able to pull data from the cloud, they need CASB because prevent confidential data from leaving company-controlled systems, and help protect the integrity of that data. Relevant technologies for this area include access control and data loss prevention (DLP)
upvoted 2 times
tutita
2 years ago
it prevents *
upvoted 1 times
...
...
adrian1188
2 years, 1 month ago
Selected Answer: C
Data Security Cloud adoption has removed many of the barriers preventing effective collaboration at distance. But as much as the seamless movement of data can be of benefit, it can also come at a tremendous cost for businesses with an interest in protecting sensitive and confidential information. While on-premises DLP solutions are designed to safeguard data, their ability to do so often does not extend to cloud services and lacks cloud context. The combination of CASB with sophisticated DLP allows IT the ability to see when sensitive content is traveling to or from the cloud, within the cloud, and cloud to cloud. By deploying security features like data loss prevention, collaboration control, access control, information rights management, encryption, and tokenization, enterprise data leaks can be minimized.
upvoted 2 times
...
CyberCEH
2 years, 1 month ago
VDI is the answer
upvoted 1 times
...
kiduuu
2 years, 2 months ago
Selected Answer: D
VDI provides a secure environment for accessing company resources, such as code repositories, from remote locations. With VDI, the code repository would be accessed through a virtual desktop hosted on the company's servers, rather than on the developer's laptop. This means that the company's IT department can control the virtual desktop and ensure that it is secure, including installing security software, monitoring activity, and limiting access to the code repository.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...