exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 162 discussion

Actual exam question from CompTIA's SY0-501
Question #: 162
Topic #: 1
[All SY0-501 Questions]

A copy of a highly confidential salary report was recently found on a printer in the IT department. The human resources department does not have this specific printer mapped to its devices, and it is suspected that an employee in the IT department browsed to the share where the report was located and printed it without authorization. Which of the following technical controls would be the BEST choice to immediately prevent this from happening again?

  • A. Implement a DLP solution and classify the report as confidential, restricting access only to human resources staff
  • B. Restrict access to the share where the report resides to only human resources employees and enable auditing
  • C. Have all members of the IT department review and sign the AUP and disciplinary policies
  • D. Place the human resources computers on a restricted VLAN and configure the ACL to prevent access from the IT department
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MichaelLangdon
Highly Voted 4 years, 6 months ago
Entry level they say...
upvoted 12 times
BlackMagicAce
1 year, 5 months ago
entry level for the big dogs
upvoted 2 times
...
...
ctux
Highly Voted 5 years, 9 months ago
I think it is B because the DLP solution is better but does not solve the problem immediately...
upvoted 7 times
...
Milletoo
Most Recent 4 years ago
B is the answer here. Restricting access to the share is the first step to prevent it from happening in the first place and auditing as well.
upvoted 2 times
...
ilu129
4 years, 1 month ago
DLP prevents end users from sending sensitive or critical info OUTSIDE of corporate network. This is occurring within.
upvoted 1 times
...
fonka
4 years, 1 month ago
IT should be A (DLP) Insider threats—data loss is increasingly caused by malicious insiders, compromised privileged accounts or accidental data sharing.
upvoted 2 times
...
fonka
4 years, 1 month ago
It should beAn administrator is configuring access to information located on a network file server named ג€Bowmanג€. The files are located in a folder named ג€BalkFilesג€. The files are only for use by the ג€Matthewsג€ division and should be read-only. The security policy requires permissions for shares to be managed at the file system layer and also requires those permissions to be set according to a least privilege model. Security policy for this data type also dictates that administrator-level accounts on the system have full access to the files. The administrator configures the file share according to the following table: Data Loss Prevention (DLP) A.
upvoted 1 times
...
chizmo
4 years, 5 months ago
The questions says that the IT department accessed a folder that they shouldn't have. So restricting access on the share folder is what the question is asking about?
upvoted 2 times
...
Hassan84
4 years, 6 months ago
It is A.
upvoted 1 times
...
Not_My_Name
4 years, 9 months ago
B is correct. This would be the quickest solution to implement. Also, many people assume that "an employee in the IT department" means the SysAdmin. There are many other roles in the IT department, and many of these don't need access to EVERYTHING.
upvoted 2 times
...
Enlightened
4 years, 9 months ago
Keyword to take notice of is, "immediately", which only points to answer B as others would take longer to implement
upvoted 4 times
Not_My_Name
4 years, 9 months ago
I agree. This would be the fastest solution.
upvoted 1 times
...
...
Autox
4 years, 11 months ago
A for me. The Data is in a database that only the HR staff can access. DLP system will make sure that the HR staff, and/or an insider threat tries to exfiltrate this information out of the secure database. C is a slap on the wrist and threats of punishment, but A prevents it from happening and employs the concept of Least Privilege.
upvoted 1 times
...
kdce
5 years ago
B, Restrict access to the share to only HR
upvoted 1 times
...
Dante_Dan
5 years, 2 months ago
If you notice, answers A, B and D would solve the problem if the one that committed the violation were a normal user. As the perpetrator is from IT, answer should be C
upvoted 1 times
MagicianRecon
5 years ago
Read the question again. Needs to be a technical control. Signing AUP is NOT technical
upvoted 1 times
...
...
MelvinJohn
5 years, 2 months ago
C - Can you set permissions to deny the Systems Administrators access? Sure. Can the Systems Administrators change it so they have access? Sure. Can it be set up to tell you who changed the access or who accessed the folder? Sure. Who are you going to have set it up and check the logs? Oh yeah, the Systems Administrators.
upvoted 1 times
...
MelvinJohn
5 years, 3 months ago
C. sign an AUP. Systems Administrators have complete access to all folders and files – and the Windows Server OS gives them permission to take ownership of any folder or file that may have tried to restrict their access. They have the authority to run the utility program “TAKEOWN” to do it. Since you can’t restrict them from accessing the share – then all you can do is get them to sign an AUP.
upvoted 1 times
covfefe
5 years, 2 months ago
Signing an AUP is not a technical control. It's more administrative.
upvoted 2 times
...
...
Neela
5 years, 3 months ago
B - even if system admin access , auditing will reveal the person who accessed
upvoted 2 times
...
MelvinJohn
5 years, 4 months ago
A. The DLP would likely include most of the solutions mentioned in the other answers - and possible more.
upvoted 1 times
MelvinJohn
5 years, 4 months ago
A. Implement a DLP solution AND classify the report as confidential, restricting access only to human resources staff.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...