exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 111 discussion

Actual exam question from CompTIA's CAS-004
Question #: 111
Topic #: 1
[All CAS-004 Questions]

A DevOps team has deployed databases, event-driven services, and an API gateway as PaaS solution that will support a new billing system.
Which of the following security responsibilities will the DevOps team need to perform?

  • A. Securely configure the authentication mechanisms.
  • B. Patch the infrastructure at the operating system.
  • C. Execute port scanning against the services.
  • D. Upgrade the service as part of life-cycle management.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mr_BuCk3th34D
Highly Voted 2 years, 4 months ago
Selected Answer: A
All answers are correct and should be done, but it looks like the questions is asking for an answer that is specific to the DevOps role. The most important security responsibility for the DevOps team in this scenario would be to securely configure the authentication mechanisms. Patching the infrastructure at the operating system level, executing port scanning against the services, and upgrading the service as part of life-cycle management are all important security responsibilities, but they are not as critical as securely configuring the authentication mechanisms in this context.
upvoted 15 times
...
beanbag
Highly Voted 2 years, 7 months ago
Selected Answer: B
in PaaS, end user manages Data, Applications ONLY. whilst provider of PaaS platform manage Middleware, Runtime, "O/S", Virtualization, Storage, Servers, Network
upvoted 6 times
Serliop378
2 years, 1 month ago
They ask what the devops need to do in a PaaS mode so patching the OS is not this responsibility model !
upvoted 3 times
...
professorx123
2 years, 1 month ago
that's the key here
upvoted 3 times
...
...
Johnny_R
Most Recent 3 months, 3 weeks ago
Selected Answer: A
This is a PaaS scenario so DevOps team certainly doesn't care about patching OS
upvoted 1 times
...
grelaman
6 months, 2 weeks ago
Selected Answer: B
In the scenario, the DevOps team has deployed databases, event-driven services, and an API gateway as a PaaS solution that will support a new billing system. This wording suggests that the DevOps team is building and providing the PaaS platform themselves, rather than consuming a PaaS offering from an external cloud service provider. They are responsible for the security of the entire platform, including the infrastructure and operating systems. Patching the infrastructure at the operating system level is a critical security responsibility to protect the platform from vulnerabilities.
upvoted 1 times
...
23169fd
9 months, 3 weeks ago
Selected Answer: A
In a PaaS environment, the DevOps team is responsible for configuring and managing the security aspects of the applications and services they deploy. This includes setting up and securing authentication mechanisms to ensure that only authorized users can access the services.
upvoted 1 times
...
bjjhighlights
1 year, 6 months ago
Selected Answer: A
Again, this is AWS shit at its finest. You don't patch AWS Lambda/API Gateway/DynamoDB, they do. You do however need to make sure your code's auth functions are correct though.
upvoted 2 times
...
BiteSize
1 year, 9 months ago
Selected Answer: A
Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 3 times
...
sadamishspic
2 years, 1 month ago
Selected Answer: A
OS is IaaS
upvoted 4 times
...
Cock
2 years, 1 month ago
Selected Answer: A
A. Securely configure the authentication mechanisms since it is a crucial security responsibility that DevOps teams need to perform to prevent unauthorized access to the billing system.
upvoted 3 times
...
chil7chil7
2 years, 3 months ago
Selected Answer: A
Service Provider manages OS
upvoted 3 times
...
AnnoyingIAGuy
2 years, 3 months ago
Selected Answer: A
A. Patching is performed by the Sys admins, so wouldn't go with B
upvoted 4 times
...
DaleC78
2 years, 3 months ago
Selected Answer: A
It can't be B; Patching the infrastructure at the OS is done by the CSP in the PaaS model.
upvoted 4 times
...
atebyasandwich
2 years, 4 months ago
I think if anything it's A. I see people vote B but that's usually taken cared by sys admins.
upvoted 4 times
...
kycugu
2 years, 4 months ago
I would recommend "A. Securely configure the authentication mechanisms." Properly configuring the authentication mechanisms is critical for ensuring that only authorized users can access the billing system. If the authentication mechanisms are not properly configured, it could lead to security vulnerabilities and potentially allow unauthorized users to access the system. In contrast, the other options, while important for maintaining the security of the billing system, are not as crucial for ensuring that the system is only accessible to authorized users.
upvoted 2 times
...
EZPASS
2 years, 4 months ago
I agree. I'm also leaning towards A. DevOps team's number one responsibility is to ensure all the services/systems they deploy is configured securely before they can worry about patching. In this case A.
upvoted 3 times
...
atebyasandwich
2 years, 4 months ago
Selected Answer: A
It makes the most sense. That or D. B more sounds like something an infrastructure team would do.
upvoted 2 times
...
ryanzou
2 years, 5 months ago
Selected Answer: B
B is the answer, I am responsible for patch installation as a DevOps
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago