ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 473 - CAS-004 discussion

Report
Export

A security analyst identified a vulnerable and deprecated runtime engine that is supporting a public-facing banking application. The developers anticipate the transition to modern development environments will take at least a month. Which of the following controls would best mitigate the risk without interrupting the service during the transition?

A.
Shutting down the systems until the code is ready
Answers
A.
Shutting down the systems until the code is ready
B.
Uninstalling the impacted runtime engine
Answers
B.
Uninstalling the impacted runtime engine
C.
Selectively blocking traffic on the affected port
Answers
C.
Selectively blocking traffic on the affected port
D.
Configuring IPS and WAF with signatures
Answers
D.
Configuring IPS and WAF with signatures
Suggested answer: D

Explanation:

Given the vulnerability in the deprecated runtime engine, configuring an IPS (Intrusion Prevention System) and WAF (Web Application Firewall) with appropriate signatures is the best temporary control. This allows the organization to monitor and block potential attacks targeting known vulnerabilities in the runtime engine while the developers work on the transition. Shutting down the systems or uninstalling the runtime engine would cause service interruptions, and blocking traffic might disrupt legitimate users. IPS and WAF provide an active layer of defense without interrupting service. CASP+ emphasizes the use of layered security, including IPS and WAF, to mitigate risks in public-facing applications.

CASP+ CAS-004 Exam Objectives: Domain 3.0 -- Enterprise Security Architecture (Web Application Firewalls, Intrusion Prevention Systems)

CompTIA CASP+ Study Guide: Mitigating Application Vulnerabilities with WAFs and IPS

asked 02/10/2024
Abdulilah Alhousainy
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first