問題文
An admin wants to reduce the risk that a malicious or over-permissioned app compromises company data. How does app governance connect directly to security?
選択肢
- Allow all apps to install freely and monitor them afterward, because reviewing apps before installation provides no security benefit and any malicious or over-permissioned app can always be fully contained by simply watching the installed-apps list after it has already connected and used its granted access.
- Require app approval and review scopes before installation, because vetting apps at the point of connection prevents over-permissioned or untrusted apps from ever gaining access.
- Give apps broad scopes so they never fail, improving both reliability and security at once, and an app that already holds every permission it might one day want will never return an error and errors are the only real security problem a workspace has.
- Rely on encryption alone; app scopes do not affect security, and also data that is encrypted in transit and at rest cannot be read by anything, so what an installed app is permitted to do makes no difference.