ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 60 - CAS-004 discussion

Report
Export

A financial institution has several that currently employ the following controls:

* The severs follow a monthly patching cycle.

* All changes must go through a change management process.

* Developers and systems administrators must log into a jumpbox to access the servers hosting the data using two-factor authentication.

* The servers are on an isolated VLAN and cannot be directly accessed from the internal production network.

An outage recently occurred and lasted several days due to an upgrade that circumvented the approval process. Once the security team discovered an unauthorized patch was installed, they were able to resume operations within an hour. Which of the following should the security administrator recommend to reduce the time to resolution if a similar incident occurs in the future?

A.
Require more than one approver for all change management requests.
Answers
A.
Require more than one approver for all change management requests.
B.
Implement file integrity monitoring with automated alerts on the servers.
Answers
B.
Implement file integrity monitoring with automated alerts on the servers.
C.
Disable automatic patch update capabilities on the servers
Answers
C.
Disable automatic patch update capabilities on the servers
D.
Enhanced audit logging on the jump servers and ship the logs to the SIEM.
Answers
D.
Enhanced audit logging on the jump servers and ship the logs to the SIEM.
Suggested answer: B
asked 02/10/2024
Maurice Nicholson
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first