exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 157 discussion

Actual exam question from CompTIA's CAS-004
Question #: 157
Topic #: 1
[All CAS-004 Questions]

A security analyst needs to recommend a remediation to the following threat:

Which of the following actions should the security analyst propose to prevent this successful exploitation?

  • A. Patch the system.
  • B. Update the antivirus.
  • C. Install a host-based firewall.
  • D. Enable TLS 1.2.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 2 years, 2 months ago
Selected Answer: A
This is Directory Traversal and Command Injection attack You want to reconfigure your web server, AKA patch the system.
upvoted 6 times
...
23169fd
Most Recent 6 months, 2 weeks ago
Selected Answer: A
Apply security patches: Ensure that the web application and any underlying frameworks or software are updated to fix known vulnerabilities.
upvoted 1 times
...
jt2oux
1 year, 4 months ago
Was going to go with host-based firewall until I looked up the definition of system patch. That sways my answer towards A. Patch the system. Patches are intended to repair vulnerabilities or flaws identified after the release of an application or software, upgrade and optimize the system for better efficiency and, most important, mitigate any potential security vulnerabilities.
upvoted 1 times
...
[Removed]
2 years, 2 months ago
Selected Answer: A
The answer cant be: C because the question clearly states that "organization requires a legacy system to incorporate reference data into a new system" an air-gapped system can't incorporate reference data into the new system. jump-boxes are usually placed in the DMZ but they can be placed anywhere believed to have a high risk of being compromised. A jump server is an intermediary device responsible for funneling traffic through firewalls using a supervised secure channel. By creating a barrier between networks, jump servers create an added layer of security against outsiders wanting to maliciously access sensitive company data
upvoted 2 times
...
Sloananne
2 years, 3 months ago
Selected Answer: A
Looks like command injection over HTTP. You need to patch the system frequently or use a WAF or input validation.
upvoted 3 times
...
adamwella
2 years, 4 months ago
TLS 1.2 is outdated so would not be the answer.
upvoted 2 times
...
troy9876
2 years, 4 months ago
Selected Answer: D
TLS should be the answer.
upvoted 1 times
adamwella
2 years, 4 months ago
Not sure how TLS fixes this problem. However, if you patch this vulnerability then the problem is solved.
upvoted 5 times
...
AaronS1990
1 year, 7 months ago
No it shouldn't be. Also compTIA recommends TLS 1.3 and above
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago