exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 8 discussion

Actual exam question from CompTIA's CAS-004
Question #: 8
Topic #: 1
[All CAS-004 Questions]

A security analyst is reviewing the following output:

Which of the following would BEST mitigate this type of attack?

  • A. Installing a network firewall
  • B. Placing a WAF inline
  • C. Implementing an IDS
  • D. Deploying a honeypot
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Winterz
Highly Voted 3 years, 3 months ago
The Answer is B
upvoted 14 times
zapato
3 years, 3 months ago
I agree. A WAF would be correct answer.
upvoted 4 times
...
...
BiteSize
Highly Voted 7 months, 3 weeks ago
Selected Answer: B
CASP #1 answer I keep seeing over and over... Place a WAF inline. Provide Input Validation to stop the bad guys from running exploits. Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 8 times
...
salmonIsDecent
Most Recent 7 months, 3 weeks ago
Selected Answer: B
I selected B. Placing a WAF inline because a WAF is specifically designed to inspect HTTP/HTTPS requests, detect and block common web application attacks which includes directory traversal attempts as seen in this captured log. The WAF can analyze the URL structure, recognize the malicious patterns and prevent the request from reaching the web server.
upvoted 1 times
...
Delab202
7 months, 3 weeks ago
Selected Answer: B
The provided output indicates an attempt to access sensitive files on a web server, such as "/etc/password," which could be indicative of a directory traversal or path traversal attack. To best mitigate this type of attack, the most appropriate option is: B. Placing a WAF inline (Web Application Firewall) Explanation: Web Application Firewall (WAF): A WAF is designed to protect web applications from various attacks, including directory traversal. It can inspect and filter HTTP traffic between a web application and the Internet, blocking malicious requests that attempt to access unauthorized directories or files.
upvoted 2 times
...
23169fd
10 months, 1 week ago
Selected Answer: B
Traversal attack => WAF
upvoted 2 times
...
BreakOff874
2 years ago
Answer: B. This (../../) is known as a traversal sequences and is considered a web application attack.
upvoted 3 times
...
Andre876
2 years, 6 months ago
I agree I believe the answer is a WAF
upvoted 3 times
...
ryanzou
2 years, 6 months ago
Selected Answer: B
B is correct
upvoted 3 times
...
ryanzou
2 years, 7 months ago
Selected Answer: B
The answer must be B. It's a directory traversal attack.
upvoted 4 times
...
dangerelchulo
2 years, 8 months ago
Selected Answer: B
Attack is an XSS and the best solution is OWASP, best solution available is WAF
upvoted 3 times
AaronS1990
2 years ago
It's directory traversal hence the ../ but it is still B
upvoted 2 times
...
...
AlexJacobson
2 years, 9 months ago
Selected Answer: B
I vote B, not because it eliminates LDAP injection issue (WAF can't do that, just make it harder to exploit the vulnerability in the application), but because all other answers make zero sense in this scenario. :)
upvoted 4 times
...
BLADESWIFTKNIFE
2 years, 11 months ago
Selected Answer: B
I agree
upvoted 3 times
...
Mara03
2 years, 11 months ago
Acunetix Website: The only way to effectively defend against directory traversal attacks is to carefully write the code of the website or web application and use user input sanitization libraries. Note that web application firewalls (WAF) do not eliminate directory traversal issues, just make it harder for the attacker to exploit vulnerabilities.
upvoted 4 times
...
Mara03
2 years, 11 months ago
A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in the VPN2S firewall. Zyxel has released a patch addressing directory traversal and command injection vulnerabilities in the VPN2S firewall.
upvoted 1 times
...
RevZig67
3 years ago
Selected Answer: B
Need a WAF
upvoted 2 times
...
whatupcprio
3 years, 1 month ago
Selected Answer: B
Network Firewall does not make sense in this scenario. Best mitigation from those available is the WAF.
upvoted 3 times
...
Sc0p10n
3 years, 1 month ago
The answer is definitely B. you need a web application firewall to prevent this. And from the log, we know is targeting the application layer.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago