exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 361 discussion

Actual exam question from CompTIA's CAS-004
Question #: 361
Topic #: 1
[All CAS-004 Questions]

A small software company deployed a new web application after a network security scan found no vulnerabilities. A customer using this application reported malicious activity believed to be associated with the application. During an investigation, the company discovered that the customer closed the browser tab and connected to another application, using the same credentials on both platforms. Which of the following detection methods should the software company implement before deploying the next version?

  • A. Multifactor authentication
  • B. Static application code scanning
  • C. Stronger password policy
  • D. A SIEM
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
POWNED
Highly Voted 1 year, 6 months ago
Selected Answer: D
MFA is not a detection method. I would have to go with SIEM on this one.
upvoted 7 times
...
abrub
Highly Voted 1 year, 4 months ago
Selected Answer: A
Implementing multifactor authentication adds an additional layer of security beyond just username and password. Even if a user's credentials are compromised, an extra authentication factor (such as a temporary code from a mobile app or a hardware token) provides an additional barrier to unauthorized access. This helps protect against scenarios where the user's
upvoted 5 times
...
Bright07
Most Recent 1 month, 3 weeks ago
Selected Answer: D
Sorry for the answer I selected. The question was asking for the best detection method not prevention method which makes my answer now go to D SIEM. A SIEM can collect and analyze logs from the web application, detect suspicious login patterns (e.g., credential reuse or unusual access attempts), and alert the company to potential malicious activity. It provides real-time monitoring and correlation of security events, which is critical for identifying and responding to threats.
upvoted 1 times
...
lj22HI
6 months, 2 weeks ago
Selected Answer: B
Answer is B
upvoted 2 times
...
Aliyan
6 months, 4 weeks ago
Selected Answer: B
Not A and C because its not detection its prevention. NOT D. Because SIEM is for monitoring your network devices it is an aggregation solution not to check what's wrong with your application code activity. This is totally B. Static application code scanning. (I have good enough experience in COMPTIA exams to confidently say this is B and not D)
upvoted 3 times
...
fac161f
7 months, 2 weeks ago
MFA logs login attempts.
upvoted 3 times
...
fac161f
7 months, 2 weeks ago
MFA does or can log all login attempts. Even though MFA is not primarlily considered a form of detection, it does log attempts. Aall that said, I chose B and really hate questions like this.
upvoted 2 times
...
Bright07
8 months ago
Ans A. (MFA) MFA adds an additional layer of security by requiring users to provide two or more verification factors to gain access to an application. Even if credentials are reused or compromised, MFA helps prevent unauthorized access by requiring something beyond just the username and password, such as a one-time code sent to a mobile device or an authentication app. This significantly improves the security posture of the application and mitigates risks associated with credential reuse. While A SIEM (Security Information and Event Management): SIEM system is valuable for monitoring, logging, and analyzing security events across the network and applications. While it can help detect and respond to security incidents, it does not directly prevent issues related to credential reuse or enhance authentication security.
upvoted 3 times
...
Anarckii
1 year, 4 months ago
Selected Answer: D
The company is looking for the best DETECTION method before the next release
upvoted 3 times
...
OdinAtlasSteel
1 year, 6 months ago
Selected Answer: D
By implementing a SIEM, the software company can enhance its ability to detect and respond to security incidents, including unauthorized access or malicious activity.
upvoted 2 times
...
ThatGuyOverThere
1 year, 6 months ago
Selected Answer: B
I'd have to go with B. The only hesitancy I have with B is that they say they deploy an application but don't necessarily say they developed the application. However, a static app scan with a SAST would be the best answer here. A SIEM will take logs from tools and help analysts threat hunt but I don't think that applies here for a real detection method. What would be sending to the SIEM they would detect on? It does say a software company so I'm goin to assume they have the source code. Given how much better B is for an answer when assuming they have the source code, I think it's the best choice.
upvoted 2 times
YUYUY
1 year, 3 months ago
A SAST would not detect the threat here. The question does not state the there is an issue with the code either. The issue is with the user. So because the question is asking for the best detection method D. is correct. If the question asked what is the best way to prevent this I would say C.
upvoted 1 times
CraZee
1 year, 3 months ago
While I agree with you and many others that D is the best "detection" method (and the right answer), I disagree that C is the best prevention method. I could be misinterpreting the scenario (we all know CompTIA has a way with the wording of questions), but nothing in it indicates the strength of the password that was compromised. Even the strongest password can be hijacked with the right tools and methods. To me, the best prevention is MFA...this at least forces the user to provide a secondary or tertiary form of identification. Like I said, I could be wrong....those are just my thoughts.
upvoted 2 times
...
...
...
weaponxcel
1 year, 6 months ago
Selected Answer: D
D. A SIEM. A SIEM (Security Information and Event Management) system is a tool that collects and analyzes security data from a variety of sources, such as network logs, application logs, and security devices. SIEM systems can be used to detect suspicious activity, such as unusual login patterns or failed loginhttps://www.examtopics.com/exams/comptia/cas-004/view/# attempts. Why not A. Multifactor authentication (MFA)? MFA enhances security by requiring multiple methods of verification to prove identity when logging in. While MFA can prevent unauthorized access due to stolen or guessed credentials, it doesn't address session management issues or customer's credentials were compromised.
upvoted 4 times
...
joinedatthehop
1 year, 6 months ago
Selected Answer: D
Don't let MFA fool you. The question asks, "Which of the following detection methods...". MFA is not a detection method while a SIEM is.
upvoted 3 times
...
32d799a
1 year, 6 months ago
Selected Answer: A
Given the choices and the described scenario, A. Multifactor authentication would be the most direct and effective method to prevent the described attack, as it would require an additional layer of verification even if credentials are reused across applications.
upvoted 3 times
...
CXSSP
1 year, 7 months ago
Selected Answer: A
I'm confident that implementing multifactor authentication (MFA) would be an effective measure to enhance security in this scenario. It would add an extra layer of protection by requiring users to provide multiple forms of authentication before accessing the application. This can significantly reduce the risk of unauthorized access, especially in cases where credentials might be reused across different platforms.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago