exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 143 discussion

Actual exam question from CompTIA's CAS-004
Question #: 143
Topic #: 1
[All CAS-004 Questions]

During a phishing exercise, a few privileged users ranked high on the failure list. The enterprise would like to ensure that privileged users have an extra security- monitoring control in place. Which of the following is the MOST likely solution?

  • A. A WAF to protect web traffic
  • B. User and entity behavior analytics
  • C. Requirements to change the local password
  • D. A gap analysis
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ThatGuyOverThere
10 months, 1 week ago
Selected Answer: B
UEBA would be the right answer. A WAF is more about protecting the organization's applications and not protecting users from phishing or other external web based threats. If they mentioned something with URL or content filtering it may be harder but given the options UEBA fits best.
upvoted 1 times
...
FOURDUE
1 year, 6 months ago
Selected Answer: B
Security data analytics can be used to perform basic, essential employee monitoring or more advanced techniques such as User and Entity Behavior Analytics (UEBA), analyzing network activity to detect suspicious traffic, identifying unauthorized account use, identifying account breaches, supporting threat hunting, detecting malicious insider activities, and many other similar security operations capabilities.
upvoted 3 times
...
joaks
1 year, 6 months ago
Selected Answer: B
Its user based. UEBA is the way to go.
upvoted 2 times
...
angryelvis
1 year, 8 months ago
I understand the reasoning behind choosing B - UEBA but is clicking a link an activity that "deviates from a normal baseline" but the WAF could interrupt the problem before it starts - A.
upvoted 1 times
...
[Removed]
1 year, 9 months ago
Selected Answer: B
UEBA will work better because it's doing behavior analytics on the admins unlike a WAF that protects only web traffic in this case
upvoted 3 times
AnnoyingIAGuy
1 year, 7 months ago
I like this explanation. I would also go with B
upvoted 2 times
tefyayaydu
9 months, 2 weeks ago
This explanation also points out that the question is stating it wants 'these specific users' to have extra protection, not everyone else.
upvoted 1 times
...
...
...
klosinskil
1 year, 10 months ago
Selected Answer: B
"UEBA is a type of cybersecurity solution or feature that discovers threats by identifying activity that deviates from a normal baseline"
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...