A security engineer must ensure that sensitive corporate information is not exposed if a company laptop is stolen. Which of the following actions best addresses this requirement?
Correct Answer: A
To prevent sensitive corporate information from being exposed if a laptop is stolen, the solution must ensure that data is not stored locally and access is tightly controlled. According to the CompTIA SecurityX CAS-005 study guide (Domain 4: Governance, Risk, and Compliance, 4.3), Desktop as a Service (DaaS) hosts data and applications in the cloud, reducing the risk of data exposure on physical devices. Combining DaaS with multifactor authentication (MFA) ensures that even if a laptop is stolen, unauthorized access to the cloud environment is prevented.
* Option B:IP allow lists and SSO do not address data stored locally on the laptop, which could be accessed offline.
* Option C:MDM and stronger passwords help but do not prevent data exposure if the device is compromised (e.g., via offline attacks).
* Option D:Updating policies and monitoring breaches are reactive measures that do not directly protect data on a stolen laptop.
* Option A:DaaS ensures no sensitive data resides on the device, and MFA secures access, making it the best solution.
Reference:
CompTIA SecurityX CAS-005 Official Study Guide, Domain 4: Governance, Risk, and Compliance, Section
4.3: "Implement secure data handling through cloud-based solutions like DaaS." CAS-005 Exam Objectives, 4.3: "Analyze solutions for protectingsensitive data on endpoints."