CAS-001 · Question #407
An IT administrator has been tasked by the Chief Executive Officer with implementing security using a single device based on the following requirements: 1.Selective sandboxing of suspicious code to…
The correct answer is A. UTM. A UTM (Unified Threat Management) appliance (A) is specifically designed to consolidate multiple security functions into a single device. Enterprise-grade UTMs include: (1) advanced threat protection with sandbox analysis for suspicious executables and files; (2)…
Question
An IT administrator has been tasked by the Chief Executive Officer with implementing security using a single device based on the following requirements:
1.Selective sandboxing of suspicious code to determine malicious intent. 2.VoIP handling for SIP and H.323 connections. 3.Block potentially unwanted applications. Which of the following devices would BEST meet all of these requirements?
Options
- AUTM
- BHIDS
- CNIDS
- DWAF
- EHSM
How the community answered
(40 responses)- A88% (35)
- B3% (1)
- C3% (1)
- D8% (3)
Explanation
A UTM (Unified Threat Management) appliance (A) is specifically designed to consolidate multiple security functions into a single device. Enterprise-grade UTMs include: (1) advanced threat protection with sandbox analysis for suspicious executables and files; (2) application-layer gateways (ALGs) that understand and inspect VoIP protocols such as SIP and H.323 to allow proper NAT traversal and policy enforcement; and (3) application control engines that can identify and block potentially unwanted applications (PUAs) based on deep packet inspection. HIDS (B) is a host-based intrusion detection system installed on individual hosts-it does not handle VoIP protocols or network-level PUA blocking. NIDS (C) detects intrusions passively and cannot actively block PUAs or sandbox code. WAF (D) protects only web applications. HSM (E) is a hardware security module for cryptographic key management-it has no traffic inspection capability.
Topics
Community Discussion
No community discussion yet for this question.