nerdexam
CompTIA

CAS-002 · Question #320

A small retail company recently deployed a new point of sale (POS) system to all 67 stores. The core of the POS is an extranet site, accessible only from retail stores and the corporate office over…

The correct answer is A. Deploy new perimeter firewalls at all stores with UTM functionality. Malware on store PCs is generating excessive traffic affecting both POS response times and VoIP quality, requiring a perimeter-level security solution at each store.

Technical Integration of Enterprise Components

Question

A small retail company recently deployed a new point of sale (POS) system to all 67 stores. The core of the POS is an extranet site, accessible only from retail stores and the corporate office over a split-tunnel VPN. An additional split-tunnel VPN provides bi-directional connectivity back to the main office, which provides voice connectivity for store VoIP phones. Each store offers guest wireless functionality, as well as employee wireless. Only the staff wireless network has access to the POS VPN. Recently, stores are reporting poor response times when accessing the POS application from store computers as well as degraded voice quality when making phone calls. Upon investigation, it is determined that three store PCs are hosting malware, which is generating excessive network traffic. After malware removal, the information security department is asked to review the configuration and suggest changes to prevent this from happening again. Which of the following denotes the BEST way to mitigate future malware risk?

Options

  • ADeploy new perimeter firewalls at all stores with UTM functionality.
  • BChange antivirus vendors at the store and the corporate office.
  • CMove to a VDI solution that runs offsite from the same data center that hosts the new POS
  • DDeploy a proxy server with content filtering at the corporate office and route all traffic through

How the community answered

(30 responses)
  • A
    57% (17)
  • B
    13% (4)
  • C
    23% (7)
  • D
    7% (2)

Why each option

Malware on store PCs is generating excessive traffic affecting both POS response times and VoIP quality, requiring a perimeter-level security solution at each store.

ADeploy new perimeter firewalls at all stores with UTM functionality.Correct

Deploying UTM (Unified Threat Management) firewalls at each store provides integrated perimeter security including intrusion prevention, antivirus, and traffic inspection directly at the store network edge. This addresses the root cause by detecting and blocking malicious traffic generated by infected PCs before it saturates the VPN tunnels used by the POS and VoIP systems. UTM at the store level is the most targeted and effective fix given the distributed, store-level nature of the infections.

BChange antivirus vendors at the store and the corporate office.

Changing antivirus vendors does not guarantee that the three already-infected PCs will be immediately remediated, nor does it address the network performance degradation currently in progress.

CMove to a VDI solution that runs offsite from the same data center that hosts the new POS

Moving to VDI shifts compute offsite but does not stop the malware on store PCs from continuing to generate excessive local and VPN traffic that degrades voice quality.

DDeploy a proxy server with content filtering at the corporate office and route all traffic through

Routing all traffic through a corporate proxy contradicts the split-tunnel VPN design and would increase latency for POS and voice traffic rather than resolving the malware-driven bandwidth problem.

Concept tested: UTM firewall deployment for distributed branch security

Source: https://www.cisco.com/c/en/us/products/security/firewalls/what-is-a-firewall.html

Topics

#POS security#UTM firewall#split-tunnel VPN#network performance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice