ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 238 - CAS-004 discussion

Report
Export

A security analyst at a global financial firm was reviewing the design of a cloud-based system to identify opportunities to improve the security of the architecture. The system was recently involved in a data breach after a vulnerability was exploited within a virtual machine's operating system. The analyst observed the VPC in which the system was located was not peered with the security VPC that contained the centralized vulnerability scanner due to the cloud provider's limitations. Which of the following is the BEST course of action to help prevent this situation m the near future?

A.
Establish cross-account trusts to connect all VPCs via API for secure configuration scanning.
Answers
A.
Establish cross-account trusts to connect all VPCs via API for secure configuration scanning.
B.
Migrate the system to another larger, top-tier cloud provider and leverage the additional VPC peering flexibility.
Answers
B.
Migrate the system to another larger, top-tier cloud provider and leverage the additional VPC peering flexibility.
C.
Implement a centralized network gateway to bridge network traffic between all VPCs.
Answers
C.
Implement a centralized network gateway to bridge network traffic between all VPCs.
D.
Enable VPC traffic mirroring for all VPCs and aggregate the data for threat detection.
Answers
D.
Enable VPC traffic mirroring for all VPCs and aggregate the data for threat detection.
Suggested answer: A

Explanation:

The BEST course of action for the security analyst to help prevent a similar situation in the near future is to Establish cross-account trusts to connect all VPCs via API for secure configuration scanning (A). Cross-account trusts allow for VPCs to be securely connected for the purpose of secure configuration scanning, which can help to identify and remediate vulnerabilities within the system.

asked 02/10/2024
Arnaldo Martinez 2-30793
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first