nerdexam
CompTIA

CAS-002 · Question #244

The senior security administrator wants to redesign the company DMZ to minimize the risks associated with both external and internal threats. The DMZ design must support security in depth, change…

The correct answer is A. A dual firewall DMZ with remote logging where each firewall is managed by a separate. A dual firewall DMZ with remote logging and separate administrators for each firewall best satisfies the requirements for security in depth, change management, and incident reconstruction.

Enterprise Security

Question

The senior security administrator wants to redesign the company DMZ to minimize the risks associated with both external and internal threats. The DMZ design must support security in depth, change management and configuration processes, and support incident reconstruction. Which of the following designs BEST supports the given requirements?

Options

  • AA dual firewall DMZ with remote logging where each firewall is managed by a separate
  • BA single firewall DMZ where each firewall interface is managed by a separate administrator
  • CA SaaS based firewall which logs to the company's local storage via SSL, and is managed
  • DA virtualized firewall, where each virtual instance is managed by a separate administrator

How the community answered

(38 responses)
  • A
    61% (23)
  • B
    11% (4)
  • C
    21% (8)
  • D
    8% (3)

Why each option

A dual firewall DMZ with remote logging and separate administrators for each firewall best satisfies the requirements for security in depth, change management, and incident reconstruction.

AA dual firewall DMZ with remote logging where each firewall is managed by a separateCorrect

A dual firewall DMZ places two distinct security boundaries between external and internal networks, satisfying the security-in-depth requirement by forcing an attacker to bypass two independently managed devices. Remote logging to a separate system ensures log integrity for incident reconstruction, since logs cannot be altered if the DMZ is compromised. Assigning a separate administrator to each firewall enforces separation of duties, directly supporting change management and configuration control processes.

BA single firewall DMZ where each firewall interface is managed by a separate administrator

A single firewall DMZ represents a single point of failure and does not provide security in depth, because compromising one device exposes both internal and external zones simultaneously.

CA SaaS based firewall which logs to the company's local storage via SSL, and is managed

A SaaS-based firewall introduces dependency on a third-party provider for a critical security control, which undermines internal change management processes and can complicate incident reconstruction due to limited or delayed log access.

DA virtualized firewall, where each virtual instance is managed by a separate administrator

A virtualized firewall running on a single physical host creates a single point of failure at the hardware layer, meaning a physical compromise or failure defeats all virtual instances and does not truly provide security in depth.

Concept tested: Dual firewall DMZ design for security in depth

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-41r1.pdf

Topics

#DMZ design#defense in depth#dual firewall#incident reconstruction

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice