ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 319 - CAS-004 discussion

Report
Export

A hospitality company experienced a data breach that included customer Pll. The hacker used social engineering to convince an employee to grant a third-party application access to some company documents within a cloud file storage service. Which of the following is the BEST solution to help prevent this type of attack in the future?

A.
NGFW for web traffic inspection and activity monitoring
Answers
A.
NGFW for web traffic inspection and activity monitoring
B.
CSPM for application configuration control
Answers
B.
CSPM for application configuration control
C.
Targeted employee training and awareness exercises
Answers
C.
Targeted employee training and awareness exercises
D.
CASB for OAuth application permission control
Answers
D.
CASB for OAuth application permission control
Suggested answer: D

Explanation:

The company should use CASB for OAuth application permission control to help prevent this type of attack in the future. CASB stands for cloud access security broker, which is a software tool that monitors and enforces security policies for cloud applications. CASB can help control which third-party applications can access the company's cloud file storage service and what permissions they have. CASB can also detect and block any unauthorized or malicious applications that try to access the company's data. Verified

Reference:

https://www.kaspersky.com/resource-center/threats/how-to-avoid-social-engineering-attacks

https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/understanding-preventing-social-engineering-attacks/

https://www.indusface.com/blog/10-ways-businesses-can-prevent-social-engineering-attacks/

asked 02/10/2024
Calvin Bolico
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first