exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 28 discussion

Actual exam question from CompTIA's CAS-004
Question #: 28
Topic #: 1
[All CAS-004 Questions]

A company plans to build an entirely remote workforce that utilizes a cloud-based infrastructure. The Chief Information Security Officer asks the security engineer to design connectivity to meet the following requirements:
✑ Only users with corporate-owned devices can directly access servers hosted by the cloud provider.
✑ The company can control what SaaS applications each individual user can access.
✑ User browser activity can be monitored.
Which of the following solutions would BEST meet these requirements?

  • A. IAM gateway, MDM, and reverse proxy
  • B. VPN, CASB, and secure web gateway
  • C. SSL tunnel, DLP, and host-based firewall
  • D. API gateway, UEM, and forward proxy
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
romero318
Highly Voted 2 years, 7 months ago
Selected Answer: B
So The reason I would say B is because of the first item. corporate-owned devices accessing servers directly is usually done with a VPN. This is the key factor in this question and it is the only answer with VPN. Also CASB helps a company control what cloud applications can be seen to what users.
upvoted 10 times
...
BiteSize
Highly Voted 1 year, 9 months ago
Selected Answer: B
The big what if is the interpretation of "corporate-owned devices" "accessing servers" Are the devices phones? Then it would be A., leveraging a Microsoft environment of Intune, AAD, and Sentinel. Since it doesn't say mobile I would say that with a lack of descriptors then we have to interpret that it is traditional and the answer would be B. Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 7 times
...
blacksheep6r
Most Recent 2 months, 2 weeks ago
Selected Answer: A
Why A is the Best Answer? ✔ IAM Gateway (Identity and Access Management) → Controls user authentication and ensures only corporate-owned devices can access cloud resources. ✔ MDM (Mobile Device Management) → Enforces device policies, restricting access to only approved, corporate-owned devices. ✔ Reverse Proxy → Intercepts web traffic before it reaches the SaaS applications, allowing monitoring and access control. 💡 This setup ensures secure authentication, device enforcement, and visibility into user activity.
upvoted 1 times
...
23169fd
9 months, 2 weeks ago
Selected Answer: B
VPN: Ensures secure, device-based access control. CASB: Provides granular control over SaaS applications. Secure Web Gateway: Monitors and controls user browser activity.
upvoted 1 times
...
Mr214
1 year, 8 months ago
Selected Answer: D
✑ Only users with corporate-owned devices can directly access servers hosted by the cloud provider. (UEM) ✑ The company can control what SaaS applications each individual user can access. (API Gateway) ✑ User browser activity can be monitored. (Forward Proxy)
upvoted 1 times
...
imather
1 year, 8 months ago
Selected Answer: B
Only corporate owned devices - VPN can fulfill this, especially if it is hardware-based or requires an agent installed on the asset Control SaaS application access - CASB governs cloud usage across devices and cloud applications and so can control access User browser activity monitored - this can be accomplished both through a VPN and a secure web gateway. "secure web gateways provide advanced network protection by inspecting web requests against company policy"
upvoted 3 times
...
margomi86
2 years ago
Selected Answer: B
B. VPN, CASB, and secure web gateway would be the best solution to meet the requirements. A VPN (Virtual Private Network) can restrict access to corporate-owned devices only, which would satisfy the first requirement. A CASB (Cloud Access Security Broker) would allow the company to control which SaaS applications individual users can access, fulfilling the second requirement.
upvoted 5 times
...
Broesweelies
2 years, 1 month ago
Selected Answer: A
MDM is the only viable solution for cloud based server access
upvoted 3 times
Cosmic_robot
2 years ago
That makes no sense at all. Mobile Device Management (MDM) focuses on the control of mobile devices to ensure compliance with an organizationʼs security requirements. That came straight from the CompTIA CAS-004 book. VPN, CASB, and Secure web gateway are the best options. Go with B.
upvoted 3 times
...
...
david124
2 years, 2 months ago
B. VPN, CASB, and secure web gateway would BEST meet the requirements. A VPN would ensure that only corporate-owned devices can directly access the cloud-based infrastructure. A Cloud Access Security Broker (CASB) can control the access of individual users to SaaS applications, fulfilling the second requirement. A secure web gateway can monitor user browser activity, satisfying the final requirement. The secure web gateway acts as a security layer between the users and the internet, allowing for the monitoring and controlling of web traffic and ensuring that only authorized web resources are accessible.
upvoted 4 times
...
EZPASS
2 years, 2 months ago
Selected Answer: A
A is the correct answer.
upvoted 2 times
...
lordguck
2 years, 5 months ago
Only A addresses the issue of corp owned devices.
upvoted 1 times
...
Protocol0
2 years, 5 months ago
Selected Answer: A
I believe the answer they have is correct. If they infrastructure is entirely in the cloud as it says. All can be accomplished and IAM (Azure AD) MDM (Intune) and the reverse proxy to monitor their browser.
upvoted 2 times
BiteSize
1 year, 9 months ago
Completely agree but the big what if is the interpretation of "corporate-owned devices" "accessing servers" Are the devices phones? Then yes, yours works. Since it doesn't say mobile I would say that with a lack of descriptors then we have to interpret that it is traditional and the answer would be B.
upvoted 2 times
...
...
dangerelchulo
2 years, 7 months ago
Selected Answer: B
Not sure how VPN plays a role but CASB and secure gateway seems a fit for 2 out of the 3 they need
upvoted 4 times
loganharris
1 year, 11 months ago
VPNs can be used to ensure only corporate devices connect
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago