exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 541 discussion

Actual exam question from CompTIA's CAS-004
Question #: 541
Topic #: 1
[All CAS-004 Questions]

An IDS was unable to detect malicious network traffic during a recent security incident, even though all traffic was being sent using HTTPS. As a result, a website used by employees was compromised. Which of the following detection mechanisms would allow the IDS to detect an attack like this one in the future?

  • A. Deobfuscation
  • B. Protocol decoding
  • C. Inspection proxy
  • D. Digital rights management
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
grelaman
6 months, 3 weeks ago
Selected Answer: C
An inspection proxy, often referred to as an SSL/TLS proxy or HTTPS proxy, acts as an intermediary between clients and servers. It decrypts HTTPS traffic, allowing for inspection and analysis before re-encrypting and forwarding the traffic to its destination. By decrypting HTTPS traffic, the inspection proxy enables the IDS to analyze the contents of the data packets for malicious activities. Allows for the implementation of security policies that can block or flag suspicious activities based on the decrypted content. The inspection proxy must handle SSL/TLS certificates appropriately to avoid security warnings and ensure seamless user experiences.
upvoted 3 times
...
Bright07
7 months, 1 week ago
Ans C. To enhance the ability of an IDS to detect malicious network traffic, especially in encrypted contexts like HTTPS, the best detection mechanism would be Inspection proxy. An inspection proxy can intercept and inspect encrypted traffic by establishing secure connections with both the client and the server. This allows it to decrypt, analyze, and then re-encrypt the data, making it possible to detect malicious payloads that would otherwise be hidden in HTTPS traffic.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago