exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 162 discussion

Actual exam question from CompTIA's CAS-004
Question #: 162
Topic #: 1
[All CAS-004 Questions]

A security architect was asked to modify an existing internal network design to accommodate the following requirements for RDP:
✑ Enforce MFA for RDP.
✑ Ensure RDP connections are only allowed with secure ciphers.
The existing network is extremely complex and not well segmented. Because of these limitations, the company has requested that the connections not be restricted by network-level firewalls or ACLs.
Which of the following should the security architect recommend to meet these requirements?

  • A. Implement a reverse proxy for remote desktop with a secure cipher configuration enforced.
  • B. Implement a bastion host with a secure cipher configuration enforced.
  • C. Implement a remote desktop gateway server, enforce secure ciphers, and configure to use OTP.
  • D. Implement a GPO that enforces TLS cipher suites and limits remote desktop access to only VPN users.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mr_BuCk3th34D
Highly Voted 2 years, 4 months ago
Selected Answer: C
A remote desktop gateway server is a secure network-based connection point that allows authorized users to connect to remote computers using RDP over the internet. By implementing a remote desktop gateway server, the security architect can enforce MFA for RDP connections and ensure that only secure ciphers are allowed. Additionally, by configuring the remote desktop gateway server to use OTP, the security architect can add an additional layer of security to the RDP connections. Implementing a reverse proxy for remote desktop with a secure cipher configuration enforced (option A) may improve the security of the RDP connections, but it does not specifically address the requirement to enforce MFA. Implementing a bastion host with a secure cipher configuration enforced (option B) may improve the security of the RDP connections, but it does not specifically address the requirement to enforce MFA. Implementing a GPO (Group Policy Object) that enforces TLS cipher suites and limits remote desktop access to only VPN users (option D) may improve the security of the RDP connections, but it does not specifically address the requirement to enforce MFA.
upvoted 5 times
...
23169fd
Most Recent 9 months, 2 weeks ago
Selected Answer: C
Enforcing MFA for RDP: RD Gateway can be configured to use OTP or other MFA mechanisms. Ensuring secure ciphers: RD Gateway can enforce the use of secure ciphers for RDP connections.
upvoted 2 times
...
BiteSize
1 year, 9 months ago
Selected Answer: C
Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 1 times
Zulunation
1 year, 8 months ago
when do you take you exam
upvoted 2 times
e020fdc
1 year, 2 months ago
And did you pass? I've enjoyed your comments. Straightforward and sometimes funny.
upvoted 2 times
Test1269
1 year, 2 months ago
He said he did in one of the original comments from the first few questions.
upvoted 1 times
...
...
...
...
FOURDUE
2 years, 2 months ago
Selected Answer: C
agree.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago