nerdexam
CompTIA

CAS-001 · Question #143

A new startup company with very limited funds wants to protect the organization from external threats by implementing some type of best practice security controls across a number of hosts located in…

The correct answer is A. NIPS in the production zone, HIPS in the application zone, and anti-virus / anti-malware across all. The production zone contains 10 publicly accessible UNIX web hosts that rarely change, making a Network Intrusion Prevention System (NIPS) ideal - it protects multiple hosts at the network perimeter without requiring per-host agents. The application zone has a single critical…

Technical Integration of Enterprise Components

Question

A new startup company with very limited funds wants to protect the organization from external threats by implementing some type of best practice security controls across a number of hosts located in the application zone, the production zone, and the core network. The 50 hosts in the core network are a mixture of Windows and Linux based systems, used by development staff to develop new applications. The single Windows host in the application zone is used exclusively by the production team to control software deployments into the production zone. There are 10 UNIX web application hosts in the production zone which are publically accessible. Development staff is required to install and remove various types of software from their hosts on a regular basis while the hosts in the zone rarely require any type of configuration changes. Which of the following when implemented would provide the BEST level of protection with the LEAST amount of disruption to staff?

Options

  • ANIPS in the production zone, HIPS in the application zone, and anti-virus / anti-malware across all
  • BNIPS in the production zone, NIDS in the application zone, HIPS in the core network, and anti-virus / anti-
  • CHIPS in the production zone, NIPS in the application zone, and HIPS in the core network.
  • DNIDS in the production zone, HIDS in the application zone, and anti-virus / anti-malware across all hosts.

How the community answered

(31 responses)
  • A
    84% (26)
  • B
    3% (1)
  • C
    10% (3)
  • D
    3% (1)

Explanation

The production zone contains 10 publicly accessible UNIX web hosts that rarely change, making a Network Intrusion Prevention System (NIPS) ideal - it protects multiple hosts at the network perimeter without requiring per-host agents. The application zone has a single critical Windows host controlling software deployments; Host Intrusion Prevention System (HIPS) provides tight control over that one high-value system. The core network has 50 development hosts that frequently install and remove software, which would cause HIPS to generate constant false positives and interfere with legitimate work - anti-virus/anti-malware provides a baseline without being overly restrictive. Option B puts HIPS in the core network, which conflicts with developer workflows. Option C places NIPS in the application zone (excessive for one host) and HIPS in the core network (too restrictive for developers). Option D uses only detection (NIDS/HIDS), not prevention.

Topics

#NIPS#HIPS#network zones#defense in depth

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice