nerdexam
CompTIA

CAS-001 · Question #150

A Physical Security Manager is ready to replace all 50 analog surveillance cameras with IP cameras with built-in web management. The Security Manager has several security guard desks on different…

The correct answer is C. Create an IP camera network and deploy a proxy to authenticate users prior to accessing the cameras. Since the IP cameras cannot perform user authentication natively, deploying a reverse proxy in front of the camera network compensates for this limitation. The proxy enforces authentication before forwarding requests to the cameras, allowing only verified users (security guard…

Technical Integration of Enterprise Components

Question

A Physical Security Manager is ready to replace all 50 analog surveillance cameras with IP cameras with built-in web management. The Security Manager has several security guard desks on different networks that must be able to view the cameras without unauthorized people viewing the video as well. The selected IP camera vendor does not have the ability to authenticate users at the camera level. Which of the following should the Security Manager suggest to BEST secure this environment?

Options

  • ACreate an IP camera network and deploy NIPS to prevent unauthorized access.
  • BCreate an IP camera network and only allow SSL access to the cameras.
  • CCreate an IP camera network and deploy a proxy to authenticate users prior to accessing the cameras.
  • DCreate an IP camera network and restrict access to cameras from a single management host.

How the community answered

(28 responses)
  • A
    14% (4)
  • B
    11% (3)
  • C
    71% (20)
  • D
    4% (1)

Explanation

Since the IP cameras cannot perform user authentication natively, deploying a reverse proxy in front of the camera network compensates for this limitation. The proxy enforces authentication before forwarding requests to the cameras, allowing only verified users (security guard desks) to access the video feeds, regardless of which network they are on. This provides centralized access control without requiring any changes to the cameras themselves. Option A (NIPS) prevents network intrusions but does not authenticate users to the camera feeds. Option B (SSL only) encrypts traffic in transit but does not restrict who can view the video. Option D (single management host) severely limits usability by preventing multiple guard desks from accessing the cameras simultaneously.

Topics

#IP cameras#authentication proxy#physical security systems#network access control

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice