nerdexam
CompTIA

CAS-001 · Question #478

The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is concerned that an unrecognized threat could compromise corporate data and result in…

The correct answer is D. Behavior based IPS with a communication link to a cloud based vulnerability and threat feed. A behavior-based IPS with a cloud-based vulnerability and threat feed is the correct answer. Zero-day exploits are, by definition, unknown to signature-based systems. Behavior-based detection identifies threats by analyzing anomalous activity and deviations from normal…

Enterprise Security

Question

The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is concerned that an unrecognized threat could compromise corporate data and result in regulatory fines as well as poor corporate publicity. The network is mostly flat, with split staff/guest wireless functionality. Which of the following equipment MUST be deployed to guard against unknown threats?

Options

  • ACloud-based antivirus solution, running as local admin, with push technology for definition
  • BImplementation of an offsite data center hosting all company data, as well as deployment of VDI
  • CHost based heuristic IPS, segregated on a management VLAN, with direct control of the
  • DBehavior based IPS with a communication link to a cloud based vulnerability and threat feed.

How the community answered

(51 responses)
  • A
    6% (3)
  • B
    12% (6)
  • C
    4% (2)
  • D
    78% (40)

Explanation

A behavior-based IPS with a cloud-based vulnerability and threat feed is the correct answer. Zero-day exploits are, by definition, unknown to signature-based systems. Behavior-based detection identifies threats by analyzing anomalous activity and deviations from normal baselines - it does not require prior knowledge of the specific exploit. Coupling this with a real-time cloud-based threat feed ensures the system benefits from global threat intelligence and the latest indicators of compromise. Option A (cloud antivirus) is still primarily signature-based and cannot detect truly unknown threats. Option B (offsite data center with VDI) protects data but does not prevent compromise of endpoints or detect the initial intrusion. Option C (host-based heuristic IPS on a management VLAN) has limited visibility across a mostly flat network and is isolated from the broader threat landscape. Behavior-based detection is the industry-recognized approach to combating zero-day and unknown threats.

Topics

#zero-day exploits#behavior-based IPS#threat intelligence feeds#unknown threats

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice