exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 364 discussion

Actual exam question from CompTIA's CAS-004
Question #: 364
Topic #: 1
[All CAS-004 Questions]

The Chief Information Security Officer is concerned about the possibility of employees downloading malicious files from the internet and opening them on corporate workstations. Which of the following solutions would be BEST to reduce this risk?

  • A. Integrate the web proxy with threat intelligence feeds.
  • B. Scan all downloads using an antivirus engine on the web proxy.
  • C. Block known malware sites on the web proxy.
  • D. Execute the files in the sandbox on the web proxy.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
1 month ago
Selected Answer: D
Sandboxing is a technique where files or applications are executed in an isolated environment (the "sandbox") to observe their behavior before allowing them to run on a corporate workstation. This helps detect malicious behavior, such as file manipulation or exploitation attempts, without risking the corporate network or systems. NOT B. Option B can be effective in detecting known malware signatures, but it may not catch new or sophisticated threats, such as zero-day exploits or advanced malware that doesn't match existing signatures. Thus, executing the files in the sandbox on the web proxy provides the most thorough defense against the risk of malicious files being executed on corporate workstations.
upvoted 1 times
...
Silverthorn
2 months, 1 week ago
Selected Answer: D
The question asks what is the BEST way to reduce risk. That means the option that will cover the most. There is no limiting factors such as cost, automation, or convenience to the employee which is specifically stated in other questions that are looking for those options. Sandbox is the BEST because it covers the most including zero day attacks. Malware can still get through the gaps of a firewall or by attaching itself to unknown malware sites. Sandbox stops it all making it the BEST, not the most automated or convenient.
upvoted 2 times
...
CraZee
11 months, 2 weeks ago
Selected Answer: B
I agree with those who answered B. While D is likely the SAFEST solution, I don't think it is the BEST solution considering the expectations of the company on the employees (taking hb0011's Fireeye idea out as I don't think CompTIA was pushing that in the question). B seems the BEST to me.
upvoted 2 times
...
Trap_D0_r
1 year ago
Selected Answer: B
You need an automated solution for enterprise scanning. How would you even execute every download on a sandbox? Teach each employee how to log in and test there then make them promise to never execute a file somewhere else? It's not just impractical, it's impossible, where a reverse proxy + Av engine is fairly standard industry practice.
upvoted 3 times
a18733c
1 month, 3 weeks ago
It's not impossible, it's a standard in many mature orgs to automatically sandbox downloaded files and it's better than relying on AV signatures at reducing risk.
upvoted 1 times
...
...
Anarckii
1 year ago
Selected Answer: B
We are focused on automation of ensure downloads don’t contain malware. Scanning the malware in conjunction with a web proxy to filter the content out helps this
upvoted 1 times
...
OdinAtlasSteel
1 year, 1 month ago
Selected Answer: B
Changing my answer to B. Blocking malware sites isn't comprehensive enough. Executing the files in a sandbox on the web proxy isn't practical or automated enough. The best solution is to scan all files downloaded. B.
upvoted 1 times
...
OdinAtlasSteel
1 year, 2 months ago
Selected Answer: C
C. Block known malware sites on the web proxy. Blocking known malware sites is a fundamental security measure to prevent users from accessing websites that are known to distribute malicious content. It aligns with the principle of preventing known threats from entering the network, providing a proactive defense against malware.
upvoted 1 times
...
weaponxcel
1 year, 2 months ago
Selected Answer: D
D. Execute the files in the sandbox on the web proxy. Sandboxing provides a proactive approach, evaluating files based on behavior and potentially catching malicious files that signature-based solutions might miss.
upvoted 2 times
Anarckii
1 year ago
so every download that is conducted, you're just going to sit there in a sandbox and test every one of them? that's time consuming and a waste of resources. You won't to focus on a dynamic approach and that's having the web proxy scan all downloads
upvoted 1 times
hb0011
12 months ago
Fireeye can automate sandboxing
upvoted 1 times
...
...
...
CXSSP
1 year, 3 months ago
Selected Answer: D
Option B, which involves scanning all downloads using an antivirus engine on the web proxy, is also a valid approach to reduce the risk. This method helps identify and block potentially malicious files before they reach the end-user's workstation. It provides an additional layer of protection. Both options D and B are effective, but using a sandboxed environment (option D) is often considered a more comprehensive approach for analyzing potentially harmful files.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago