nerdexam
CompTIA

CAS-001 · Question #61

After a recent outbreak of malware attacks, the Chief Information Officer (CIO) tasks the new security manager with determining how to keep these attacks from reoccurring. The company has a standard…

The correct answer is B. Conduct a vulnerability assessment of the standard image and remediate findings. Conducting a vulnerability assessment of the standard image identifies the specific weaknesses exploited by the malware, enabling targeted remediation at the root cause rather than adding generic controls.

Enterprise Security

Question

After a recent outbreak of malware attacks, the Chief Information Officer (CIO) tasks the new security manager with determining how to keep these attacks from reoccurring. The company has a standard image for all laptops/workstations and uses a host-based firewall and anti-virus. Which of the following should the security manager suggest to INCREASE each system's security level?

Options

  • AUpgrade all system's to use a HIPS and require daily anti-virus scans.
  • BConduct a vulnerability assessment of the standard image and remediate findings.
  • CUpgrade the existing NIDS to NIPS and deploy the system across all network segments.
  • DRebuild the standard image and require daily anti-virus scans of all PCs and laptops.

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    80% (24)
  • C
    3% (1)
  • D
    10% (3)

Why each option

Conducting a vulnerability assessment of the standard image identifies the specific weaknesses exploited by the malware, enabling targeted remediation at the root cause rather than adding generic controls.

AUpgrade all system's to use a HIPS and require daily anti-virus scans.

Adding HIPS and daily AV scans improves detection but does not identify or fix the underlying vulnerabilities in the standard image that enabled the infection.

BConduct a vulnerability assessment of the standard image and remediate findings.Correct

A vulnerability assessment of the standard image directly surfaces the configuration flaws and unpatched components that allowed the malware outbreak to occur. Remediating those findings hardens the baseline deployed to every workstation, closing the actual attack surface. This addresses the root cause rather than layering detection tools on top of a still-vulnerable image.

CUpgrade the existing NIDS to NIPS and deploy the system across all network segments.

Upgrading from NIDS to NIPS is a network-perimeter control and does nothing to remediate host-level weaknesses present in the workstation image.

DRebuild the standard image and require daily anti-virus scans of all PCs and laptops.

Rebuilding the image without first assessing it recreates the same insecure baseline, and daily AV scans alone cannot prevent exploitation of unpatched vulnerabilities.

Concept tested: Vulnerability assessment and secure baseline image hardening

Source: https://csrc.nist.gov/publications/detail/sp/800-40/rev-4/final

Topics

#vulnerability assessment#endpoint security#malware mitigation#HIPS

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice