exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 181 discussion

Actual exam question from CompTIA's SY0-501
Question #: 181
Topic #: 1
[All SY0-501 Questions]

A security administrator has been tasked with improving the overall security posture related to desktop machines on the network. An auditor has recently that several machines with confidential customer information displayed in the screens are left unattended during the course of the day.
Which of the following could the security administrator implement to reduce the risk associated with the finding?

  • A. Implement a clean desk policy
  • B. Security training to prevent shoulder surfing
  • C. Enable group policy based screensaver timeouts
  • D. Install privacy screens on monitors
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jemusu
3 years, 10 months ago
B not C why? because there are companies who have a policy of 'don't leave your desk without locking your pc' (even if it wasn't stated in here). Also, B (being aware of shoulder surfing) also includes locking your computer whenever you are not using it and not letting your computer open to everyone when you are processing confidential data.
upvoted 1 times
...
fonka
4 years ago
Answer is A because the key word is left unattended meaning what should be done when an emplee take 15 mint meal or smoking break? Screensaver do not exclusively solve the problem because you still have insider malicious people out there. Yes clear screen policy is also part of clear desk polic A clean desk policy (CDP) is a corporate directive that specifies how employees should leave their working space when they leave the office. Most CDPs require employees to clear their desks of all papers at the end of the day.
upvoted 2 times
...
YogiT
4 years ago
The k word here is "to reduce" So, the answer is C.
upvoted 1 times
...
leon4579
4 years, 2 months ago
E All of the above
upvoted 4 times
...
who__cares123456789___
4 years, 5 months ago
Answer is correct...SYS admin controls technical and logical controls like group policy time outs on screens....PS Should surfing is NOT relegated to mobile phones like Nikki says! But that is not what is at issue here....issue here is unattended screen...in a mobile device, we would implement lock screen policy on paper but enforce with MDM....youre welcome
upvoted 1 times
...
choboanon
4 years, 9 months ago
Shouldn't the answer be D, installing privacy screens? It isn't shoulder surfing because someone needs to be present looking over your shoulder. It isn't clean desk policy because that's at the end of the day. A screen saver timeout does lessen the risk of information being left on the screen but a screen privacy filter does a better job of this. If there's a screensaver there's a timer on it which doesn't kick in automatically. If someone walks away from their desk and the timer is 3 minutes, that's 3 minutes the information is left on screen for anyone to see. A privacy filter is always active and someone has to go and sit in front of the computer to see the information. Also in the case of a screen saver, if I walk over to the desk and flick the mouse to turn the screen saver off and walk away, that's another few minutes the information is left on the screen for people to see. A privacy filter is always on.
upvoted 1 times
choboanon
4 years, 9 months ago
nevermind, I'm thinking of screensavers as not having a lock on them!
upvoted 1 times
...
...
adriantdf
4 years, 9 months ago
The complete answer should be B & C. C alone can't solve this one.
upvoted 1 times
Dedutch
4 years, 3 months ago
C doesn't really help that much. The computer is unattended so they could just go sit at it, or walk at an angle that the privacy screen doesn't prevent them seeing whats written. I think the bigger issue would be not having a screen lock out policy.
upvoted 1 times
...
...
CyberKelev
5 years ago
privacy screen monitors it's a prevention of shoulder surfing and it's not shoulder surfing in this case.
upvoted 2 times
...
george7n
5 years ago
This should be B. Security awareness training to prevent shoulder surfing As for C. Enable group policy based screensaver timeouts => tey usually kick-in after 5 or 10 mins inactivity (by this time, many things can happen)
upvoted 2 times
CyberKelev
5 years ago
no it can't be shoulder surfing because it's screen left unatended. Shoulder surfing imply that somebody look over the shoulder of the employee
upvoted 3 times
...
SimonR2
5 years ago
Agreed, but this is only to REDUCE the risk, not eliminate it. Therefore using group policy to enforce a shorter timeout helps reduce the risk.
upvoted 1 times
...
MagicianRecon
4 years, 11 months ago
The computers are left unattended. Shoulder surfing is when someone is present at their desk, typing something and someone peeks over the shoulder
upvoted 3 times
...
...
Qabil
5 years, 1 month ago
Code left unattended during the course of the day.
upvoted 1 times
...
nickyjohn
5 years, 5 months ago
Clean desk is concerned with people having p-words with sticky notes on them, names and account numbers, etc.. Shoulder surfing is more concerned with mobile phones, implies two people looking at one screen, privacy screens on monitors do no reduce risk of employees leaving unattended workstation.
upvoted 3 times
...
Basem
5 years, 9 months ago
Does clean desk policy include screen saver timeout ? Shouldn't the answer be reducd the timeout threshold ? Maybe that is what C trying to say ?
upvoted 2 times
CyberKelev
5 years ago
clean desk policy is the policy who say what the employee have to do at the end of the day
upvoted 1 times
who__cares123456789___
4 years, 4 months ago
Lead2Pass has C...and here is explanation...Security admin cant schedule training, he could only request it for upper management approval...security guy can okay installing privacy screens as this too would have to involve upper management...only tool in his hands is his group policy settings...he can do that and it wont cost a dime! The other stuff cost money and needs manager approval....changing a group policy does not...Also a clean desk policy cant be changed at will by this guy...these policies are company policy that is written and he cant just change, or implement that!! Again, he could request that through upper management..... Hope this helps
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...