nerdexam
CompTIA

CAS-001 · Question #407

An IT administrator has been tasked by the Chief Executive Officer with implementing security using a single device based on the following requirements: 1.Selective sandboxing of suspicious code to…

The correct answer is A. UTM. A UTM (Unified Threat Management) appliance (A) is specifically designed to consolidate multiple security functions into a single device. Enterprise-grade UTMs include: (1) advanced threat protection with sandbox analysis for suspicious executables and files; (2)…

Technical Integration of Enterprise Components

Question

An IT administrator has been tasked by the Chief Executive Officer with implementing security using a single device based on the following requirements:

1.Selective sandboxing of suspicious code to determine malicious intent. 2.VoIP handling for SIP and H.323 connections. 3.Block potentially unwanted applications. Which of the following devices would BEST meet all of these requirements?

Options

  • AUTM
  • BHIDS
  • CNIDS
  • DWAF
  • EHSM

How the community answered

(40 responses)
  • A
    88% (35)
  • B
    3% (1)
  • C
    3% (1)
  • D
    8% (3)

Explanation

A UTM (Unified Threat Management) appliance (A) is specifically designed to consolidate multiple security functions into a single device. Enterprise-grade UTMs include: (1) advanced threat protection with sandbox analysis for suspicious executables and files; (2) application-layer gateways (ALGs) that understand and inspect VoIP protocols such as SIP and H.323 to allow proper NAT traversal and policy enforcement; and (3) application control engines that can identify and block potentially unwanted applications (PUAs) based on deep packet inspection. HIDS (B) is a host-based intrusion detection system installed on individual hosts-it does not handle VoIP protocols or network-level PUA blocking. NIDS (C) detects intrusions passively and cannot actively block PUAs or sandbox code. WAF (D) protects only web applications. HSM (E) is a hardware security module for cryptographic key management-it has no traffic inspection capability.

Topics

#UTM#sandboxing#VoIP security#unified threat management

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice