Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SY0-601 topic 1 question 295 discussion

Actual exam question from CompTIA's SY0-601
Question #: 295
Topic #: 1
[All SY0-601 Questions]

The Chief Executive Officer (CEO) of an organization would like staff members to have the flexibility to work from home anytime during business hours, including during a pandemic or crisis. However, the CEO is concerned that some staff members may take advantage of the flexibility and work from high-risk countries while on holiday or outsource work to a third-party organization in another country. The Chief Information Officer (CIO) believes the company can implement some basic controls to mitigate the majority of the risk. Which of the following would be BEST to mitigate the CEO's concerns? (Choose two.)

  • A. Geolocation
  • B. Time-of-day restrictions
  • C. Certificates
  • D. Tokens
  • E. Geotagging
  • F. Role-based access controls
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
560exam
Highly Voted 1 year, 5 months ago
Selected Answer: AB
The correct answer is AB imo. Geolocation , Time of day restriction.
upvoted 16 times
[Removed]
1 year, 5 months ago
I agree with AB
upvoted 1 times
...
...
demianUY
Highly Voted 7 months ago
Selected Answer: AC
Most people chose AB, but I believe that is incorrect. The question presents TWO issues to address: 1) Ensuring that employees do not work from a high-risk country while on vacation. 2) Preventing employees from outsourcing their work. The Geolocation answer addresses the first concern of the CISO, which is to prevent employees from working from other countries or high-risk countries. The other chosen answer (time of day restrictions) does not address the second concern of the CISO. Therefore, among the remaining answers, the only one that seems to address that concern is certificate-based authentication, which would allow only authorized devices with the installed certificate to work and connect to the company, preventing a third party from doing so.
upvoted 13 times
klinkklonk
3 months, 3 weeks ago
Geolocation prevents high risk countries and outsourcing. The CEO wants work done only during business hours also. So it's AB
upvoted 1 times
...
LinkinTheStinkin
3 months, 1 week ago
It's A & B ... "work from home anytime during business hours,"
upvoted 2 times
...
...
NetworkTester1235
Most Recent 1 month ago
Selected Answer: AB
AB. Reasoning: The CEO wants staff to be able to work from home "anytime during business hours", and away from "high-risk countries". Time of day restriction fits with B, Geolocation fits with the location.
upvoted 1 times
...
_deleteme_
2 months, 3 weeks ago
Key words "high risk country" and "Outsource work to a 3rd party". Geolocation covers the high risk country and would also include the time and day of the country. Certificates takes care of making sure the work is not outsourced because it binds to the users ID.
upvoted 1 times
...
6809276
2 months, 3 weeks ago
Selected Answer: AC
AC because the CEO allow "anytime of day" which eliminate time of day restriction.
upvoted 1 times
64d2259
1 month, 3 weeks ago
" anytime during business hours" Business hours are not the same depending on your time zome
upvoted 1 times
...
...
klinkklonk
3 months, 3 weeks ago
Selected Answer: AB
Geolocation to stop outsourcing. Time ODR as the CEO only wants people working during business hours.
upvoted 1 times
...
shaneo007
4 months, 1 week ago
Answer A. Geolocation F. Role-based access controls
upvoted 1 times
...
RobDoc
4 months, 2 weeks ago
Selected Answer: AC
I think is A and C A) Geolocation: this would help in restricting access based on the physical location. C) Certificates: This can help mitigate the risk of unauthorized access, especially from third-party organizations. How does "Time of day restriction" address the concern of preventing employees from outsourcing work to a third-party organization?
upvoted 5 times
bb6a612
1 week, 1 day ago
I thought so too, but it states that the third-party is located in another country, so that falls under geolocation.
upvoted 1 times
...
...
TheExile
5 months ago
Selected Answer: AC
Geolocation will prevent users from operating inside high risk countries and certificates will prevent the outsourcing of work to 3rd party organizations.
upvoted 1 times
...
Teleco0997
6 months ago
Selected Answer: AB
this question is also a few pages before a bit differently worded agreed it is A and B
upvoted 1 times
...
sujon_london
8 months, 4 weeks ago
Selected Answer: AB
These two are priority basis over others
upvoted 1 times
...
maynas
9 months, 2 weeks ago
answers are B and F. B. Time-of-day restrictions: Implementing time-of-day restrictions would allow the organization to define specific business hours during which staff members are allowed to work from home. Outside of these hours, remote access could be limited or restricted entirely, reducing the likelihood of staff members working from high-risk countries during non-business hours or while on holiday. F. Role-based access controls: Role-based access controls (RBAC) would help the organization control and limit the activities that staff members can perform based on their roles and responsibilities. By defining appropriate access rights and permissions for each role, the CEO can ensure that staff members do not have the ability to outsource work to third-party organizations or perform tasks that are beyond their designated responsibilities.
upvoted 2 times
...
MyBJ
9 months, 2 weeks ago
Answer is C & E. The risks are "...work from high-risk countries while on holiday or outsource work to a third-party organization in another country." The first issue will be addressed by Geotagging and the outsourcing risk will definitely be prevented by validating the certificates.
upvoted 1 times
...
ApplebeesWaiter1122
10 months, 3 weeks ago
Selected Answer: AB
A. Geolocation: Implementing geolocation controls can help restrict access based on the physical location of the users. By defining approved locations or blocking high-risk countries, the organization can ensure that remote work is limited to authorized regions. B. Time-of-day restrictions: Enforcing time-of-day restrictions can limit remote access to specific business hours or predefined timeframes. This control ensures that employees cannot work from any location outside of designated working hours.
upvoted 4 times
sarah2023
8 months, 3 weeks ago
Isn't this the defenition of Geofencing though?
upvoted 2 times
Afel_Null
7 months, 1 week ago
Geolocating is just determining location via GPS. Geofencing is actively blocking access based on GPS. Geotagging is adding geographical information to other data. Geofencing would be better, but we don't have that as an answer.
upvoted 2 times
ballap
3 months, 3 weeks ago
If Geolocating is just "determining a location" it isn"t a security measure is it. We can"t just use this coz geofencing isn't there. If anyone can explain how geolocation is a security measure, please explain
upvoted 1 times
...
...
...
...
user82
1 year ago
Chatgpt says B and F. When I pressed further it said A could also be an answer but the best two answers are B and F.
upvoted 3 times
...
workhard
1 year, 1 month ago
I agree that AB is the answer. The reason why I chose B (Time-of-day restrictions) is that the CEO would like people to work from home anytime DURING BUSINESS HOURS, which makes sense because having people connecting to the corporate network 24/7 could create the need for more security monitoring and become expensive for the company if they dont need people working outside business hours.
upvoted 1 times
AmesCB
9 months, 2 weeks ago
your selections do not address the fact that they can outsource work to a third-party organization in another country. what if the third party org works within their business hours?
upvoted 2 times
Afel_Null
7 months, 1 week ago
That's what geolocation is for. The only other option is access control, but how exactly is it going to stop someone from sending data to other firm to work on it, then send results? You'd need to use thin-clients, or VDI with restricted access.
upvoted 1 times
...
...
...
SOCK1
1 year, 1 month ago
Selected Answer: BF
RBAC can limit access to sensitive company information and resources to only those employees who require it for their job function. Employees will not be able to outsource work
upvoted 3 times
klinkklonk
3 months, 3 weeks ago
But if they outsourced their work, they would have provided their login details etc and whoever used those would have access to the same permissions.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...