CAS-001 · Question #449
An administrator's company has recently had to reduce the number of Tier 3 help desk technicians available to support enterprise service requests. As a result, configuration standards have declined…
The correct answer is B. Disable command execution G. BIOS security I. IdM. The scenario describes an insider threat scenario where an authorized user (not an external attacker) could leverage default/misconfigured systems to perform reconnaissance. The three correct controls are: (B) Disable command execution - removes access to CLI tools like…
Question
An administrator's company has recently had to reduce the number of Tier 3 help desk technicians available to support enterprise service requests. As a result, configuration standards have declined as administrators develop scripts to troubleshoot and fix customer issues. The administrator has observed that several default configurations have not been fixed through applied group policy or configured in the baseline. Which of the following are controls the administrator should recommend to the organization's security manager to prevent an authorized user from conducting internal reconnaissance on the organization's network? (Select THREE).
Options
- ANetwork file system
- BDisable command execution
- CPort security
- DTLS
- ESearch engine reconnaissance
- FNIDS
- GBIOS security
- HHIDS
- IIdM
How the community answered
(25 responses)- A20% (5)
- B60% (15)
- C12% (3)
- F4% (1)
- H4% (1)
Explanation
The scenario describes an insider threat scenario where an authorized user (not an external attacker) could leverage default/misconfigured systems to perform reconnaissance. The three correct controls are: (B) Disable command execution - removes access to CLI tools like netstat, ping, ipconfig, and nslookup that are commonly used for internal reconnaissance; (G) BIOS security - locks down system firmware to prevent users from booting into alternate OS environments or modifying hardware configurations that could bypass OS-level controls; (I) IdM (Identity Management) - enforces role-based access control and least privilege, ensuring users can only access resources appropriate to their role, limiting what an insider can discover. The distractors are incorrect because: NFS (A) is a file-sharing protocol, not a control; Port security (C) and TLS (D) address network-level concerns, not user-level command access; Search engine reconnaissance (E) is an attack technique, not a control; NIDS (F) and HIDS (H) detect intrusions but do not prevent an authorized user from issuing legitimate-looking reconnaissance commands.
Topics
Community Discussion
No community discussion yet for this question.