ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 379 - CAS-004 discussion

Report
Export

A financial institution generates a list of newly created accounts and sensitive information on a daily basis. The financial institution then sends out a file containing thousands of lines of data. Which of the following would be the best way to reduce the risk of a malicious insider making changes to the file that could go undetected?

A.
Write a SIEM rule that generates a critical alert when files are created on the application server.
Answers
A.
Write a SIEM rule that generates a critical alert when files are created on the application server.
B.
Implement a FIM that automatically generates alerts when the file is accessed by IP addresses that are not associated with the application.
Answers
B.
Implement a FIM that automatically generates alerts when the file is accessed by IP addresses that are not associated with the application.
C.
Create a script that compares the size of the file on an hourly basis and generates alerts when changes are identified.
Answers
C.
Create a script that compares the size of the file on an hourly basis and generates alerts when changes are identified.
D.
Tune the rules on the host-based IDS for the application server to trigger automated alerts when the application server is accessed from the internet.
Answers
D.
Tune the rules on the host-based IDS for the application server to trigger automated alerts when the application server is accessed from the internet.
Suggested answer: B

Explanation:

File Integrity Monitoring (FIM) is a technology that can detect changes in files, often used to safeguard critical data. Implementing a FIM solution that generates alerts for access by unauthorized IP addresses would ensure that any unauthorized modifications to the file can be detected and acted upon. This helps in mitigating the risk of insider threats, as it would alert to any changes not made through the expected application process.

asked 02/10/2024
Robert Fox
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first