A Chief Information Security Officer (CISO) asks the security architect to design a method for contractors to access the company's internal wiki, corporate directory, and email services securely without allowing access to systems beyond the scope of their project.
Which of the following methods would BEST fit the needs of the CISO?
Click on the arrows to vote for the correct answer
A. B. C. D.A.
The BEST method for contractors to access the company's internal wiki, corporate directory, and email services securely without allowing access to systems beyond the scope of their project would be a Virtual Desktop Infrastructure (VDI), represented by option D.
A VDI solution enables users to access a virtual desktop environment hosted on a centralized server. The contractors will access the virtual desktop environment through their local devices, and all applications and data will remain stored and protected in the data center. The VDI environment can be locked down to prevent contractors from accessing resources outside of the scope of their project. The security architect can define a specific access policy that specifies which applications and data contractors can access.
Compared to other options, VDI offers more granular control and isolation of contractor access to company resources. In contrast, VPN, represented by option A, would allow contractors to access the company's internal network resources directly, which would be less secure and would increase the risk of unauthorized access. Platform-as-a-Service (PaaS), represented by option B, and Infrastructure-as-a-Service (IaaS), represented by option C, are not applicable to the scenario presented in the question, as they both relate to the deployment of cloud-based resources, which is not relevant in the context of contractor access.