ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 148 - CAS-004 discussion

Report
Export

An organization's existing infrastructure includes site-to-site VPNs between datacenters. In the past year, a sophisticated attacker exploited a zero-day vulnerability on the VPN concentrator. Consequently, the Chief Information Security Officer (CISO) is making infrastructure changes to mitigate the risk of service loss should another zero-day exploit be used against the VPN solution.

Which of the following designs would be BEST for the CISO to use?

A.
Adding a second redundant layer of alternate vendor VPN concentrators
Answers
A.
Adding a second redundant layer of alternate vendor VPN concentrators
B.
Using Base64 encoding within the existing site-to-site VPN connections
Answers
B.
Using Base64 encoding within the existing site-to-site VPN connections
C.
Distributing security resources across VPN sites
Answers
C.
Distributing security resources across VPN sites
D.
Implementing IDS services with each VPN concentrator
Answers
D.
Implementing IDS services with each VPN concentrator
E.
Transitioning to a container-based architecture for site-based services
Answers
E.
Transitioning to a container-based architecture for site-based services
Suggested answer: A

Explanation:

If on VPN concentrator goes down due to a zero day threat, having a redundant VPN concentrator of a different vendor should keep you going.

asked 02/10/2024
Ali S Zahedi
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first