Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CAS-004 topic 1 question 180 discussion

Actual exam question from CompTIA's CAS-004
Question #: 180
Topic #: 1
[All CAS-004 Questions]

A security engineer needs to implement a CASB to secure employee user web traffic. A key requirement is that the relevant event data must be collected from existing on-premises infrastructure components and consumed by the CASB to expand traffic visibility. The solution must be highly resilient to network outages.
Which of the following architectural components would BEST meet these requirements?

  • A. Log collection
  • B. Reverse proxy
  • C. A WAF
  • D. API mode
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Mr_BuCk3th34D
Highly Voted 1 year, 4 months ago
Selected Answer: A
The architectural component that would best meet these requirements is log collection. A log collection system can gather event data from various on-premises infrastructure components and send it to the CASB for analysis and visibility. A log collection system can also be designed to be highly resilient to network outages, ensuring that data is collected and sent to the CASB even in the event of an outage
upvoted 8 times
...
TomasValtor
Most Recent 1 month ago
Answer: A Check this article which describes all the CASB deployment modes. Pag. 9 https://era.library.ualberta.ca/items/199f33ce-010c-412d-93d2-b5d16b7fd927/view/10195851-63af-492a-b456-fbf535bd6947/Wason_2020_Spring_MISSM.pdf
upvoted 1 times
...
surfuganda
1 month, 1 week ago
Selected Answer: B
Don't underthink it either. B. Reverse proxy: Relevant event data collection: Reverse proxies sit in the data path between clients and servers, allowing them to intercept and log all incoming and outgoing web traffic. This enables comprehensive collection of relevant event data related to user web traffic. Resilience to network outages: Reverse proxies are designed to be highly resilient to network outages. They can queue and buffer requests during outages, ensuring minimal disruption to traffic visibility. Additionally, they can handle failover scenarios and maintain service availability even in the event of network disruptions. Reverse proxies excel in meeting both requirements: they effectively collect relevant event data from existing on-premises infrastructure components and offer high resilience to network outages.
upvoted 1 times
...
ThatGuyOverThere
6 months, 4 weeks ago
Selected Answer: B
Log collection won't allow the CASB to control access the way it needs to, in real time. Plus every time I research CASB deployment modes it's always proxy (forward or reverse) and API. API would involve changes on the SaaS side so that doesn't fit with the question, therefore Reverse Proxy must be the answer.
upvoted 2 times
ThatGuyOverThere
6 months, 2 weeks ago
I strike my decision on this after further research. Log Collection collection is an option and I'm changing my answer to that.
upvoted 2 times
...
...
32d799a
7 months, 1 week ago
Selected Answer: B
Given the described scenario where event data must be collected from on-premises components and consumed by the CASB to expand traffic visibility, and resilience to network outages is a requirement, the Reverse proxy (B) mode would be the best architectural component. It provides real-time interception, evaluation, and enforcement of policies on web traffic, which aligns with the requirements.
upvoted 1 times
...
BiteSize
10 months ago
Selected Answer: A
Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 2 times
...
FOURDUE
1 year, 3 months ago
Selected Answer: A
voting A because of this reason within the question: A key requirement is that the relevant event data must be collected from existing on-premises infrastructure components and consumed by the CASB to expand traffic visibility. the KEY requirement is that relevant event data must be collected from existing on-premises infrastructure... EVENT data.. EVT files are log files.. dont read too much into this.
upvoted 3 times
...
david124
1 year, 3 months ago
Selected Answer: B
While log collection can provide valuable information for security monitoring, it does not provide visibility into user web traffic in real-time. A reverse proxy, on the other hand, can provide real-time visibility and control over web traffic, making it a better option to meet the requirements described in the scenario. Additionally, a reverse proxy can provide high resilience to network outages as it can be designed with redundancy and failover capabilities.
upvoted 2 times
FOURDUE
1 year, 3 months ago
go to this link https://forcepoint.github.io/docs/casb_and_azure_sentinel/#step-2--configuration-for-casb-log-forwarder and read about CASB Step 2 – Configuration for CASB Log Forwarder
upvoted 1 times
Sepu
10 months ago
This is for sending Forcepoint CASB logs to Azure Sentinel (SIEM). It doesn't apply to this scenario. B imo.
upvoted 1 times
Sepu
10 months ago
Forget about that. Reverse proxy won't help either. The option would be to collect the logs and manually submit them to the CASB tool. https://portal.bitglass.com/admin/admindocs/Default.htm#NUI/Analyze/Discovery%20Report%20Page.htm?TocPath=Analyze%257CDiscovery%2520Portal%257C_____1 Changing to A.
upvoted 2 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...