nerdexam
ExamsCAS-002Questions#155
CompTIA

CAS-002 · Question #155

CAS-002 Question #155: Real Exam Question with Answer & Explanation

The correct answer is C: Create an IP camera network and deploy a proxy to authenticate users prior to accessing. Since the camera vendor does not support authentication at the camera level, authentication must be enforced at a layer in front of the cameras. Deploying a reverse proxy server that authenticates users before forwarding their requests to the cameras compensates for this limitati

Question

A Physical Security Manager is ready to replace all 50 analog surveillance cameras with IP cameras with built-in web management. The Security Manager has several security guard desks on different networks that must be able to view the cameras without unauthorized people viewing the video as well. The selected IP camera vendor does not have the ability to authenticate users at the camera level. Which of the following should the Security Manager suggest to BEST secure this environment?

Options

  • ACreate an IP camera network and deploy NIPS to prevent unauthorized access.
  • BCreate an IP camera network and only allow SSL access to the cameras.
  • CCreate an IP camera network and deploy a proxy to authenticate users prior to accessing
  • DCreate an IP camera network and restrict access to cameras from a single management

Explanation

Since the camera vendor does not support authentication at the camera level, authentication must be enforced at a layer in front of the cameras. Deploying a reverse proxy server that authenticates users before forwarding their requests to the cameras compensates for this limitation. Guards on all networks authenticate to the proxy, which controls access to the camera feeds. Option A (NIPS) prevents network intrusion but does not authenticate users. Option B (SSL only) encrypts traffic but does not authenticate who accesses the streams. Option D (single management host) is too restrictive - guards on different networks need access, and this would centralize a single point of failure.

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice