exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 211 discussion

Actual exam question from CompTIA's CAS-004
Question #: 211
Topic #: 1
[All CAS-004 Questions]

A hospitality company experienced a data breach that included customer PII. The hacker used social engineering to convince an employee to grant a third-party application access to some company documents within a cloud file storage service Which of the following is the BEST solution to help prevent this type of attack in the future?

  • A. NGFW for web traffic inspection and activity monitoring
  • B. CSPM for application configuration control
  • C. Targeted employee training and awareness exercises
  • D. CASB for OAuth application permission control
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
FOURDUE
Highly Voted 2 years, 2 months ago
Selected Answer: C
ANSWER IS C... FROM THE STUDENT GUIDE ON SOCIAL ENGINEERING Social engineering (SE) attacks are designed to exploit people in any number of creative ways. Social engineering attacks are some of the most successful types of attacks used by adversaries, and the best protections include recurring end-user training and awareness, the use of internally developed SE campaigns to identify vulnerabilities among employee and staff, and the principle of least privilege to limit the potential damage that can be done if an end-user is successfully attacked.
upvoted 7 times
...
jekster
Highly Voted 2 years, 2 months ago
Selected Answer: C
I would choose C because the root cause of the issue is the employee being tricked into giving access. Any thoughts?
upvoted 7 times
...
Bright07
Most Recent 8 months, 2 weeks ago
C. Targeted employee training and awareness exercises: This is the most effective solution because social engineering relies on manipulating human behavior. Training employees to recognize and respond appropriately to phishing attempts and other social engineering tactics can significantly reduce the risk of similar breaches occurring in the future. D. CASB for OAuth application permission control: A Cloud Access Security Broker (CASB) can help manage and control application permissions, but if employees are not aware of the risks and how to recognize social engineering attacks, they may still inadvertently grant access. Therefore, while implementing technical controls is important, educating employees through targeted training and awareness exercises is essential to effectively mitigate the risk of social engineering attacks.
upvoted 1 times
...
userguy890
1 year, 2 months ago
Selected Answer: D
it asks the BEST solution. Whenever comptia says this there's always two answers but they want the one that is recommended. the CASB is better since it will block any user from ever doing this again.
upvoted 1 times
...
ThatGuyOverThere
1 year, 6 months ago
Selected Answer: D
Putting in controls to block known methods of social engineering is better than training the user to not fall for it. As an example, you should use phishing resistant 2FA over just trying your users not to fall for phishing that can compromise their 2FA.
upvoted 2 times
...
Ariel235788
1 year, 6 months ago
Selected Answer: C
The BEST solution to help prevent this type of attack in the future is: C. Targeted employee training and awareness exercises. Here's why: Social Engineering Attack: The data breach in this scenario occurred due to a social engineering attack where an employee was manipulated into granting access to a third-party application. Social engineering attacks rely on human factors, and technical solutions alone may not fully prevent them. Employee Training and Awareness: Targeted employee training and awareness exercises are essential for educating employees about the risks associated with social engineering, phishing, and unauthorized data access. Training can help employees recognize and resist manipulation attempts, such as granting access to sensitive data to unknown or unverified third-party applications.
upvoted 1 times
Ariel235788
1 year, 6 months ago
D does address app but does not address ROOT cause
upvoted 1 times
...
...
imather
1 year, 9 months ago
Selected Answer: D
A CASB can vet and monitor OAuth application permissions https://techcommunity.microsoft.com/t5/security-compliance-and-identity/managing-risky-3rd-party-app-permissions-with-microsoft-s-casb/ba-p/276401
upvoted 1 times
imather
1 year, 8 months ago
Re-thinking this, answer is C. The employee in question could have been a technician with management capabilities over the CASB. Training is better.
upvoted 3 times
...
...
last_resort
2 years ago
Selected Answer: C
Employee training...technical controls will not prevent an inside user from falling victim to social engineering.
upvoted 3 times
...
[Removed]
2 years, 1 month ago
It's definitely C
upvoted 2 times
...
Cock
2 years, 1 month ago
Selected Answer: C
In this scenario, the hacker was able to trick an employee into granting access to company documents through social engineering. This could have been prevented if the employee had been trained to recognize the signs of social engineering attacks and had been made aware of the importance of preserving the confidentiality of customer PII.
upvoted 3 times
...
OneSaint
2 years, 2 months ago
Selected Answer: C
Training employees.
upvoted 3 times
...
kayezkay
2 years, 2 months ago
Selected Answer: D
another vote for d
upvoted 1 times
...
EZPASS
2 years, 2 months ago
Selected Answer: D
D is correct.
upvoted 1 times
Ariel235788
1 year, 6 months ago
D does not address root cause of the issue. CASB can be bypassed in a different method still via SE
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago