exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 180 discussion

Actual exam question from CompTIA's CAS-004
Question #: 180
Topic #: 1
[All CAS-004 Questions]

A security engineer needs to implement a CASB to secure employee user web traffic. A key requirement is that the relevant event data must be collected from existing on-premises infrastructure components and consumed by the CASB to expand traffic visibility. The solution must be highly resilient to network outages.
Which of the following architectural components would BEST meet these requirements?

  • A. Log collection
  • B. Reverse proxy
  • C. A WAF
  • D. API mode
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mr_BuCk3th34D
Highly Voted 1 year, 10 months ago
Selected Answer: A
The architectural component that would best meet these requirements is log collection. A log collection system can gather event data from various on-premises infrastructure components and send it to the CASB for analysis and visibility. A log collection system can also be designed to be highly resilient to network outages, ensuring that data is collected and sent to the CASB even in the event of an outage
upvoted 10 times
...
BiteSize
Highly Voted 1 year, 3 months ago
Selected Answer: A
Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 5 times
...
TomasValtor
Most Recent 6 months, 1 week ago
Answer: A Check this article which describes all the CASB deployment modes. Pag. 9 https://era.library.ualberta.ca/items/199f33ce-010c-412d-93d2-b5d16b7fd927/view/10195851-63af-492a-b456-fbf535bd6947/Wason_2020_Spring_MISSM.pdf
upvoted 2 times
...
surfuganda
6 months, 2 weeks ago
Selected Answer: B
Don't underthink it either. B. Reverse proxy: Relevant event data collection: Reverse proxies sit in the data path between clients and servers, allowing them to intercept and log all incoming and outgoing web traffic. This enables comprehensive collection of relevant event data related to user web traffic. Resilience to network outages: Reverse proxies are designed to be highly resilient to network outages. They can queue and buffer requests during outages, ensuring minimal disruption to traffic visibility. Additionally, they can handle failover scenarios and maintain service availability even in the event of network disruptions. Reverse proxies excel in meeting both requirements: they effectively collect relevant event data from existing on-premises infrastructure components and offer high resilience to network outages.
upvoted 3 times
...
ThatGuyOverThere
1 year ago
Selected Answer: B
Log collection won't allow the CASB to control access the way it needs to, in real time. Plus every time I research CASB deployment modes it's always proxy (forward or reverse) and API. API would involve changes on the SaaS side so that doesn't fit with the question, therefore Reverse Proxy must be the answer.
upvoted 2 times
ThatGuyOverThere
11 months, 3 weeks ago
I strike my decision on this after further research. Log Collection collection is an option and I'm changing my answer to that.
upvoted 2 times
...
...
32d799a
1 year ago
Selected Answer: B
Given the described scenario where event data must be collected from on-premises components and consumed by the CASB to expand traffic visibility, and resilience to network outages is a requirement, the Reverse proxy (B) mode would be the best architectural component. It provides real-time interception, evaluation, and enforcement of policies on web traffic, which aligns with the requirements.
upvoted 1 times
...
FOURDUE
1 year, 8 months ago
Selected Answer: A
voting A because of this reason within the question: A key requirement is that the relevant event data must be collected from existing on-premises infrastructure components and consumed by the CASB to expand traffic visibility. the KEY requirement is that relevant event data must be collected from existing on-premises infrastructure... EVENT data.. EVT files are log files.. dont read too much into this.
upvoted 5 times
...
david124
1 year, 8 months ago
Selected Answer: B
While log collection can provide valuable information for security monitoring, it does not provide visibility into user web traffic in real-time. A reverse proxy, on the other hand, can provide real-time visibility and control over web traffic, making it a better option to meet the requirements described in the scenario. Additionally, a reverse proxy can provide high resilience to network outages as it can be designed with redundancy and failover capabilities.
upvoted 2 times
FOURDUE
1 year, 8 months ago
go to this link https://forcepoint.github.io/docs/casb_and_azure_sentinel/#step-2--configuration-for-casb-log-forwarder and read about CASB Step 2 – Configuration for CASB Log Forwarder
upvoted 1 times
Sepu
1 year, 3 months ago
This is for sending Forcepoint CASB logs to Azure Sentinel (SIEM). It doesn't apply to this scenario. B imo.
upvoted 1 times
Sepu
1 year, 3 months ago
Forget about that. Reverse proxy won't help either. The option would be to collect the logs and manually submit them to the CASB tool. https://portal.bitglass.com/admin/admindocs/Default.htm#NUI/Analyze/Discovery%20Report%20Page.htm?TocPath=Analyze%257CDiscovery%2520Portal%257C_____1 Changing to A.
upvoted 4 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago