ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 485 - CAS-004 discussion

Report
Export

A company's Chief Information Security Officer wants to prevent the company from being the target of ransomware. The company's IT assets need to be protected. Which of the following are the most secure options to address these concerns? (Select three).

A.
Antivirus
Answers
A.
Antivirus
B.
EDR
Answers
B.
EDR
C.
Sand boxing
Answers
C.
Sand boxing
D.
Application control
Answers
D.
Application control
E.
Host-based firewall
Answers
E.
Host-based firewall
F.
IDS
Answers
F.
IDS
G.
SIEM
Answers
G.
SIEM
H.
Strong authentication
Answers
H.
Strong authentication
Suggested answer: B, C, D

Explanation:

To prevent ransomware attacks and protect IT assets, the most secure options are:

Endpoint Detection and Response (EDR): Provides advanced threat detection, real-time monitoring, and response capabilities, which can help identify and mitigate ransomware attacks before they spread.

Sandboxing: Isolates suspicious files or software in a controlled environment where they can be analyzed for malicious behavior without affecting production systems.

Application Control: Ensures that only whitelisted, trusted applications can run, which can prevent ransomware from executing unauthorized or malicious code. Together, these controls provide a robust defense against ransomware by addressing detection, isolation, and prevention. CASP+ emphasizes the importance of combining detection and prevention strategies to mitigate sophisticated attacks like ransomware.

CASP+ CAS-004 Exam Objectives: Domain 2.0 -- Enterprise Security Operations (Endpoint Protection, Ransomware Mitigation)

CompTIA CASP+ Study Guide: Mitigating Ransomware with EDR, Sandboxing, and Application Control

asked 02/10/2024
Pachara Suwannasit
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first