exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 88 discussion

Actual exam question from CompTIA's CAS-004
Question #: 88
Topic #: 1
[All CAS-004 Questions]

A pharmaceutical company recently experienced a security breach within its customer-facing web portal. The attackers performed a SQL injection attack and exported tables from the company's managed database, exposing customer information.
The company hosts the application with a CSP utilizing the IaaS model. Which of the following parties is ultimately responsible for the breach?

  • A. The pharmaceutical company
  • B. The cloud software provider
  • C. The web portal software vendor
  • D. The database software vendor
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
snilu
Highly Voted 3 years, 2 months ago
If it's using IaaC, the company is managing their systems including the web portal. Why the CSP is responsible???
upvoted 10 times
...
BotWayne
Highly Voted 2 years, 8 months ago
Selected Answer: A
IaaS = Infrastructure as a Service. So the CSP provided the hardware. What the pharmaceutical company puts on that hardware is their business. The fact it was breached via SQL injection, i.e. software coding, means it's the web application was the point of ingress. Therefore, it's the onus of the Pharma company.
upvoted 7 times
...
Orean
Most Recent 9 months, 3 weeks ago
With an IaaS model, the customer is responsible for EVERYTHING barring the physical cloud-hosting hardware (which falls within the CSP's scope). Since the CSP's hardware has practically nothing to do with the SQLi vulnerability, the blame falls on the customer.
upvoted 1 times
...
23169fd
12 months ago
Selected Answer: A
In the IaaS model, while the CSP ensures the infrastructure's security, the pharmaceutical company is responsible for securing its application, including protecting against SQL injection attacks
upvoted 1 times
...
23169fd
12 months ago
In the IaaS model, while the CSP ensures the infrastructure's security, the pharmaceutical company is responsible for securing its application, including protecting against SQL injection attacks
upvoted 1 times
...
Delab202
1 year, 5 months ago
Selected Answer: A
Customer Responsibilities: Application Security: The pharmaceutical company is responsible for securing its customer-facing web portal and the application code. This includes protecting against common vulnerabilities like SQL injection through proper input validation, parameterized queries, and other secure coding practices. Data Security: The security of customer information stored in the database is the responsibility of the customer. This includes implementing proper access controls, encryption, and ensuring data is not exposed due to vulnerabilities like SQL injection.
upvoted 1 times
...
BiteSize
1 year, 11 months ago
Selected Answer: A
The data owner is responsible for the data. Also even more responsible than normal because the CSP only provides Infrastructure. All patching of systems and security is supposed to be conducted by the customer in a IaaS. Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 1 times
...
dangerelchulo
2 years, 10 months ago
Selected Answer: A
IaaS means that the responsibility is passed onto the costumer this case the Pharma Company. Scenario also only indicates that the database is managed by the company but doesn't explain who controls the web page. When sql injection happens is due to poorly coded user interface in the web and not the database manager. I will say that the one at fault is the Web developer there fore they are responsible. I could also make the case that the company is responsible for hiring a bad Web developer. Can't decide if A or C
upvoted 4 times
...
EZPASS
2 years, 10 months ago
Selected Answer: A
I agree. A is the correct answer.
upvoted 2 times
...
Agrona
2 years, 11 months ago
Selected Answer: A
In the Shared Responsibility model, this would fall under the company's responsibility.
upvoted 2 times
...
RevZig67
3 years, 1 month ago
Selected Answer: A
The company is managing the DB.
upvoted 5 times
...
jbandin696969
3 years, 2 months ago
I believe the pharmaceutical company is responsible for their own data in a IaaS model. https://www.techtarget.com/searchcloudcomputing/feature/The-cloud-shared-responsibility-model-for-IaaS-PaaS-and-SaaS https://www.techtarget.com/searchcloudcomputing/feature/The-cloud-shared-responsibility-model-for-IaaS-PaaS-and-SaaS
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...