CAS-002 · Question #320
A small retail company recently deployed a new point of sale (POS) system to all 67 stores. The core of the POS is an extranet site, accessible only from retail stores and the corporate office over…
The correct answer is A. Deploy new perimeter firewalls at all stores with UTM functionality. Malware on store PCs is generating excessive traffic affecting both POS response times and VoIP quality, requiring a perimeter-level security solution at each store.
Question
A small retail company recently deployed a new point of sale (POS) system to all 67 stores. The core of the POS is an extranet site, accessible only from retail stores and the corporate office over a split-tunnel VPN. An additional split-tunnel VPN provides bi-directional connectivity back to the main office, which provides voice connectivity for store VoIP phones. Each store offers guest wireless functionality, as well as employee wireless. Only the staff wireless network has access to the POS VPN. Recently, stores are reporting poor response times when accessing the POS application from store computers as well as degraded voice quality when making phone calls. Upon investigation, it is determined that three store PCs are hosting malware, which is generating excessive network traffic. After malware removal, the information security department is asked to review the configuration and suggest changes to prevent this from happening again. Which of the following denotes the BEST way to mitigate future malware risk?
Options
- ADeploy new perimeter firewalls at all stores with UTM functionality.
- BChange antivirus vendors at the store and the corporate office.
- CMove to a VDI solution that runs offsite from the same data center that hosts the new POS
- DDeploy a proxy server with content filtering at the corporate office and route all traffic through
How the community answered
(30 responses)- A57% (17)
- B13% (4)
- C23% (7)
- D7% (2)
Why each option
Malware on store PCs is generating excessive traffic affecting both POS response times and VoIP quality, requiring a perimeter-level security solution at each store.
Deploying UTM (Unified Threat Management) firewalls at each store provides integrated perimeter security including intrusion prevention, antivirus, and traffic inspection directly at the store network edge. This addresses the root cause by detecting and blocking malicious traffic generated by infected PCs before it saturates the VPN tunnels used by the POS and VoIP systems. UTM at the store level is the most targeted and effective fix given the distributed, store-level nature of the infections.
Changing antivirus vendors does not guarantee that the three already-infected PCs will be immediately remediated, nor does it address the network performance degradation currently in progress.
Moving to VDI shifts compute offsite but does not stop the malware on store PCs from continuing to generate excessive local and VPN traffic that degrades voice quality.
Routing all traffic through a corporate proxy contradicts the split-tunnel VPN design and would increase latency for POS and voice traffic rather than resolving the malware-driven bandwidth problem.
Concept tested: UTM firewall deployment for distributed branch security
Source: https://www.cisco.com/c/en/us/products/security/firewalls/what-is-a-firewall.html
Topics
Community Discussion
No community discussion yet for this question.