exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 379 discussion

Actual exam question from CompTIA's CAS-004
Question #: 379
Topic #: 1
[All CAS-004 Questions]

A company wants to improve the security of its web applications that are running on in-house servers. A risk assessment has been performed, and the following capabilities are desired:

• Terminate SSL connections at a central location
• Manage both authentication and authorization for incoming and outgoing web service calls
• Advertise the web service API
• Implement DLP and anti-malware features

Which of the following technologies will be the BEST option?

  • A. WAF
  • B. XML gateway
  • C. ESB gateway
  • D. API gateway
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
OdinAtlasSteel
Highly Voted 1 year, 5 months ago
Selected Answer: D
While other technologies like WAF (Web Application Firewall), XML gateways, and ESB (Enterprise Service Bus) gateways serve specific purposes in terms of security and integration, an API gateway provides a comprehensive solution that aligns well with the listed capabilities required for enhancing the security of web applications, managing API access, and ensuring robust protection against various threats and vulnerabilities associated with web services and APIs.
upvoted 6 times
...
Steel16
Most Recent 1 month, 4 weeks ago
Selected Answer: D
o API gateway provides centralized control over API access, managing authentication, authorization, security policies, and other functions. It can handle SSL termination at a central location, advertise the web service API, and implement security features like DLP and anti-malware. o A. WAF (Web Application Firewall): While a WAF is important for securing web applications from attacks like SQL injection and XSS, it primarily focuses on protecting applications at the application layer. It doesn't offer the same level of comprehensive API management and control as an API gateway.
upvoted 3 times
...
23169fd
9 months, 3 weeks ago
Selected Answer: D
Terminating SSL connections: API gateways can centrally manage SSL/TLS termination, which simplifies the management of certificates and offloads the processing burden from backend services. Authentication and Authorization: API gateways often come with built-in support for managing authentication (e.g., OAuth, JWT) and authorization, ensuring secure access control for both incoming and outgoing web service calls. Advertising APIs: API gateways can expose and document APIs, often integrating with API developer portals to advertise and provide access to APIs. Implementing DLP and Anti-malware: Many API gateways can integrate with security tools to provide data loss prevention (DLP) and anti-malware scanning, helping to ensure the integrity and security of the data being transmitted.
upvoted 4 times
23169fd
9 months, 3 weeks ago
WAF does not handle SSL termination, API advertisement, or comprehensive authentication and authorization management.
upvoted 3 times
...
...
saucehozz
1 year ago
Selected Answer: C
C) ESB (Enterprise Service Bus) provides each desired capability.
upvoted 1 times
...
saucehozz
1 year ago
Selected Answer: D
None of the options tick every box. However, some API gateways provide plugins that allow integration with solutions that meet the company's requirements.
upvoted 4 times
saucehozz
1 year ago
I was wrong. C) ESB (Enterprise Service Bus) provides each desired capability.
upvoted 1 times
...
...
ElDirec
1 year, 2 months ago
Selected Answer: A
The BEST option for the company to improve the security of its web applications would be D. API Gateway. An API Gateway can terminate SSL connections at a central location, manage both authentication and authorization for incoming and outgoing web service calls, advertise the web service API, and implement Data Loss Prevention (DLP) and anti-malware features. It acts as a single entry point for all defined APIs and can provide centralized security mechanisms. While the other options (WAF, XML gateway, ESB gateway) can provide some level of security, they do not offer the comprehensive set of capabilities that an API Gateway does.
upvoted 2 times
...
guwno
1 year, 3 months ago
I'm choosing D. WAF just doesn't seems that it can handle each dot.
upvoted 3 times
...
Potato42
1 year, 4 months ago
Selected Answer: A
After careful considerations, I'm going for A. Even though D ticks the first 3 boxes perfectly, I don't know of any API Gateway solution that provides anti-malware services by default. A WAF would potentially be able to handle all of the requirements.
upvoted 1 times
...
Anarckii
1 year, 4 months ago
Selected Answer: A
The only thing a differentiates this question from A and D is “anti-malware features” which will most of the time be offered by a WAF
upvoted 1 times
Anarckii
1 year, 4 months ago
just some clarification An API Gateway, by itself, is not typically designed to handle Data Loss Prevention (DLP) and anti-malware features. API Gateways are primarily focused on managing and securing API traffic, including functions such as authentication, authorization, rate limiting, and traffic routing. While API Gateways play a crucial role in securing API communication, they may not have built-in capabilities for content inspection, DLP, or anti-malware.
upvoted 1 times
...
...
nuel_12
1 year, 5 months ago
Selected Answer: A
A is the best choice
upvoted 2 times
BadgerTester
1 year, 5 months ago
Can a WAF "advertise the web service API?" I ask, because the question seems to imply that it is D. Simply because the API gateway could be a WAF and whatever else is needed to satisfy the bullet points. Making D seem like the better choice. API Gateway - special cloud-based service that is used to centralize the functions provided by the APIs.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago