nerdexam
CompTIA

CAS-001 · Question #357

Company XYZ has transferred all of the corporate servers, including web servers, to a cloud hosting provider to reduce costs. All of the servers are running unpatched, outdated versions of Apache…

The correct answer is A. All servers are unpatched and running old versions. Unpatched, outdated web servers represent the most directly exploitable risk because known vulnerabilities in old Apache versions have public exploits readily available-attackers can compromise them with minimal effort. The financial data (B) is protected by encryption at rest…

Research and Analysis

Question

Company XYZ has transferred all of the corporate servers, including web servers, to a cloud hosting provider to reduce costs. All of the servers are running unpatched, outdated versions of Apache. Furthermore, the corporate financial data is also hosted by the cloud services provider, but it is encrypted when not in use. Only the DNS server is configured to audit user and administrator actions and logging is disabled on the other virtual machines. Given this scenario, which of the following is the MOST significant risk to the system?

Options

  • AAll servers are unpatched and running old versions.
  • BFinancial data is processed without being encrypted.
  • CLogging is disabled on critical servers.
  • DServer services have been virtualized and outsourced.

How the community answered

(38 responses)
  • A
    63% (24)
  • B
    11% (4)
  • C
    5% (2)
  • D
    21% (8)

Explanation

Unpatched, outdated web servers represent the most directly exploitable risk because known vulnerabilities in old Apache versions have public exploits readily available-attackers can compromise them with minimal effort. The financial data (B) is protected by encryption at rest, so that risk is already mitigated. Disabled logging (C) is a serious compliance and forensic issue but is a detection/response gap, not a direct attack vector. Virtualization and outsourcing (D) are standard, accepted practices and are not inherently a security risk when managed properly. Patching is foundational: no other control compensates for running software with known, unmitigated vulnerabilities.

Topics

#cloud security#patch management#risk assessment#server hardening

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice