Exit CAS-004 CompTIA Advanced Security Practitioner (CASP+)
Question 1 of 5
0% complete
Q1 Multiple choice

A municipal department receives telemetry data from a third-party provider.
The server collecting telemetry sits in the municipal departments screened network and accepts connections from the third party over HTTPS. The daemon has a code execution vulnerability from a lack of input sanitization of out-of-bound messages, and therefore, the cybersecurity engineers would like to Implement nsk mitigations.
Which of the following actions, if combined, would BEST prevent exploitation of this vulnerability?
(Select TWO).

Select all that apply.

  • A

    Implementing a TLS inspection proxy on-path to enable monitoring and policy enforcement

  • B

    Creating a Linux namespace on the telemetry server and adding to it the servicing HTTP daemon

  • C

    Installing and configuring filesystem integrity monitoring service on the telemetry server

  • D

    Implementing an EDR and alert on Identified privilege escalation attempts to the SIEM

  • E

    Subscribing to a UTM service that enforces privacy controls between the internal network and the screened subnet

  • F

    Using the published data schema to monitor and block off nominal telemetry messages

Previous Next