ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 446 - CAS-004 discussion

Report
Export

An IDS was unable to detect malicious network traffic during a recent security incident, even though all traffic was being sent using HTTPS. As a result, a website used by employees was compromised. Which of the following detection mechanisms would allow the IDS to detect an attack like this one in the future?

A.
Deobfuscation
Answers
A.
Deobfuscation
B.
Protocol decoding
Answers
B.
Protocol decoding
C.
Inspection proxy
Answers
C.
Inspection proxy
D.
Digital rights management
Answers
D.
Digital rights management
Suggested answer: C

Explanation:

An inspection proxy, also known as an SSL/TLS inspection proxy, can decrypt HTTPS traffic, allowing the IDS to analyze the content for malicious activity. This method ensures that encrypted traffic can be inspected without compromising the security of the data in transit. The inspection proxy will re-encrypt the data before sending it on to its destination, maintaining the confidentiality of the communication while enabling security tools to perform their functions.

CompTIA CASP+ CAS-004 Exam Objectives: Section 3.3: Integrate network and security components and implement security controls.

CompTIA CASP+ Study Guide, Chapter 7: Analyzing Security Incidents.

asked 02/10/2024
Hitesh Karangiya
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first