ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 255 - CS0-003 discussion

Report
Export

A company is concerned with finding sensitive file storage locations that are open to the public. The current internal cloud network is flat. Which of the following is the best solution to secure the network?

A.
Implement segmentation with ACLs.
Answers
A.
Implement segmentation with ACLs.
B.
Configure logging and monitoring to the SIEM.
Answers
B.
Configure logging and monitoring to the SIEM.
C.
Deploy MFA to cloud storage locations.
Answers
C.
Deploy MFA to cloud storage locations.
D.
Roll out an IDS.
Answers
D.
Roll out an IDS.
Suggested answer: A

Explanation:

Implementing segmentation with ACLs is the best solution to secure the network. Segmentation is the process of dividing a network into smaller subnetworks, or segments, based on criteria such as function, location, or security level. Segmentation can help improve the network performance, scalability, and manageability, as well as enhance the network security by isolating the sensitive or critical data and systems from the rest of the network. ACLs are Access Control Lists, which are rules or policies that specify which users, devices, or applications can access a network segment or resource, and which actions they can perform.ACLs can help enforce the principle of least privilege, and prevent unauthorized or malicious access to the network segments or resources12. Configuring logging and monitoring to the SIEM, deploying MFA to cloud storage locations, and rolling out an IDS are all good security practices, but they are not the best solution to secure the network. Logging and monitoring to the SIEM can help detect and analyze the network events and incidents, but they do not prevent them. MFA can help authenticate the users who access the cloud storage locations, but it does not protect the network from attacks or breaches.IDS can help identify and alert the network intrusions, but it does not block them34.Reference:Network Segmentation: What It Is and How to Do It Right,What is an Access Control List (ACL)? | IBM,What is SIEM? | Microsoft Security,What is Multifactor Authentication (MFA)? | Duo Security, [What is an Intrusion Detection System (IDS)? | IBM]

asked 02/10/2024
Amine Alami
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first