exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 49 discussion

Actual exam question from CompTIA's CAS-004
Question #: 49
Topic #: 1
[All CAS-004 Questions]

A network architect is designing a new SD-WAN architecture to connect all local sites to a central hub site. The hub is then responsible for redirecting traffic to public cloud and datacenter applications. The SD-WAN routers are managed through a SaaS, and the same security policy is applied to staff whether working in the office or at a remote location. The main requirements are the following:
1. The network supports core applications that have 99.99% uptime.
2. Configuration updates to the SD-WAN routers can only be initiated from the management service.
3. Documents downloaded from websites must be scanned for malware.
Which of the following solutions should the network architect implement to meet the requirements?

  • A. Reverse proxy, stateful firewalls, and VPNs at the local sites
  • B. IDSs, WAFs, and forward proxy IDS
  • C. DoS protection at the hub site, mutual certificate authentication, and cloud proxy
  • D. IPSs at the hub, Layer 4 firewalls, and DLP
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mr_BuCk3th34D
Highly Voted 1 year, 10 months ago
To meet the requirements, the network architect should implement the following solutions: DoS protection at the hub site: To ensure the network supports core applications with 99.99% uptime, the network architect should implement DoS (denial of service) protection at the hub site. This can help to prevent DoS attacks, which can disrupt the availability of the network and its applications. Mutual certificate authentication: To ensure that configuration updates to the SD-WAN routers can only be initiated from the management service, the network architect should implement mutual certificate authentication. This involves requiring the management service to present a valid certificate before it can initiate configuration updates, and requiring the SD-WAN routers to present a valid certificate before they can accept updates. Cloud proxy: To ensure that documents downloaded from websites are scanned for malware, the network architect should implement a cloud proxy. A cloud proxy is a security service that is hosted in the cloud and can be used to inspect traffic for malware and other threats before it reaches the network.
upvoted 17 times
...
EZPASS
Highly Voted 2 years, 3 months ago
I'm leaning towards C. Any thoughts? 1. "applications that have 99.99% uptime" = DoS protection 3. "must be scanned for malware" = Cloud Proxy (Ex: zscaler)
upvoted 9 times
...
Bright07
Most Recent 5 months ago
ANS C. DoS protection at the hub site: This solution helps to prevent and mitigate Denial of Service (DoS) attacks, ensuring that the network remains available and responsive. - Mutual certificate authentication: This solution enhances security by requiring both parties (client and server) to authenticate each other using digital certificates, ensuring secure communication. - Cloud proxy: A cloud proxy acts as an intermediary between users and the internet, providing additional security measures such as content filtering, threat detection, and data loss prevention. Together, these solutions provide a comprehensive approach to network security, protecting against various threats and ensuring secure and reliable communication.
upvoted 1 times
...
Anarckii
10 months, 1 week ago
Selected Answer: C
we are talking about a SaaS model. Cloud proxy even should prove that C is the answer. Nothing else in the answer helps what so ever with the scenario
upvoted 1 times
...
BiteSize
1 year, 3 months ago
Selected Answer: C
C Meets all of the requirements Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 4 times
...
Geofab
1 year, 7 months ago
Selected Answer: C
I believe the answer is C
upvoted 3 times
...
hidady
1 year, 10 months ago
c is the correct answer
upvoted 5 times
...
Mr_BuCk3th34D
1 year, 10 months ago
Selected Answer: C
Option A (reverse proxy, stateful firewalls, and VPNs at the local sites) does not include DoS protection or a cloud proxy, which are necessary to meet the requirements. Option B (IDSs, WAFs, and forward proxy IDS) does not include mutual certificate authentication or a cloud proxy, which are necessary to meet the requirements. Option D (IPSs at the hub, Layer 4 firewalls, and DLP) does not include DoS protection or mutual certificate authentication, which are necessary to meet the requirements. Overall, the network architect should implement DoS protection at the hub site, mutual certificate authentication, and a cloud proxy to meet the requirements.
upvoted 6 times
...
[Removed]
2 years ago
Answer B: IDS can support applications that have an up time of 99% since no prevention is happening. WAF will scan documents for malware and stop them from being downloaded if malware is detected. {The hub is then responsible for redirecting traffic to public cloud and datacenter applications} can be handled by Proxy IDS answer B doesn't really handle {2. The hub is then responsible for redirecting traffic to public cloud and datacenter applications.} but it is still the best option Nevertheless, answer B is still the one that makes more sense compared to D which relies on IPS for preventing everything suspicious which goes against 99% availability and DLP has nothing to do with requirements 1, 2 and 3
upvoted 2 times
...
Scor65
2 years, 1 month ago
Selected Answer: D
D is the correct answer as we need DLP and IPS for SDWAN to fulfill the requirements.
upvoted 1 times
...
dangerelchulo
2 years, 2 months ago
Selected Answer: B
99.99 Availability so IDS over IPS when it comes to that requirement and other options seem less secured to me than IDS or IPS. WAFs since it will need react to specific application traffic from management service. Forward proxy to an IDS allow any download connection to be proxy and scan properly prior to download with an IDS. Yeah B is the best answer
upvoted 2 times
...
Big_Harambe
2 years, 4 months ago
As someone who works extensively with DLP it has nothing to do with downloading documents. The DLP solutions I've mainly used block data from being transferred from system to system using say a flash drive. A forward proxy will block certain sites which would help with that more I think.
upvoted 4 times
...
ade2901296
2 years, 7 months ago
I will select B: Documents downloaded from websites must be scanned for malware.An (IDS) is a monitoring system that detects suspicious activities and generates alerts when they are detected https://www.checkpoint.com/cyber-hub/network-security/what-is-an-intrusion-detection-system-ids/
upvoted 1 times
...
iosnet
2 years, 8 months ago
Selected Answer: D
Answer is D. IPSs prevent malwares
upvoted 1 times
klosinskil
2 years, 1 month ago
"must be scanned for malware", no mention of stoping or preventing, so b fits best
upvoted 1 times
...
...
patinho777
2 years, 9 months ago
Any thoughts about this? I think that it is D.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago