nerdexam
CompTIA

CAS-002 · Question #551

After implementing port security, restricting all network traffic into and out of a network, migrating to IPv6, installing NIDS, firewalls, spam and application filters, a security administer is…

The correct answer is A. Anti-malware/virus/spyware/spam software, as well as a host based firewall and strong. A complete server endpoint security plan requires the broadest malware coverage, a host-based firewall, and strong multi-factor authentication working together.

Enterprise Security

Question

After implementing port security, restricting all network traffic into and out of a network, migrating to IPv6, installing NIDS, firewalls, spam and application filters, a security administer is convinced that the network is secure. The administrator now focuses on securing the hosts on the network, starting with the servers. Which of the following is the MOST complete list of end-point security software the administrator could plan to implement?

Options

  • AAnti-malware/virus/spyware/spam software, as well as a host based firewall and strong,
  • BAnti-virus/spyware/spam software, as well as a host based IDS, firewall, and strong
  • CAnti-malware/virus/spyware/spam software, as well as a host based firewall and biometric
  • DAnti-malware/spam software, as well as a host based firewall and strong, three-factor

How the community answered

(53 responses)
  • A
    72% (38)
  • B
    4% (2)
  • C
    9% (5)
  • D
    15% (8)

Why each option

A complete server endpoint security plan requires the broadest malware coverage, a host-based firewall, and strong multi-factor authentication working together.

AAnti-malware/virus/spyware/spam software, as well as a host based firewall and strong,Correct

Choice A specifies anti-malware, anti-virus, anti-spyware, and anti-spam software, which together cover the widest range of threat categories including threats that narrower terms like 'anti-virus' alone would miss. Pairing this with a host-based firewall for traffic control and strong authentication addresses protection, detection, and access control at the endpoint. No other choice combines all three layers with equally broad malware coverage.

BAnti-virus/spyware/spam software, as well as a host based IDS, firewall, and strong

Choice B uses the narrower term 'anti-virus' rather than 'anti-malware,' leaving modern malware categories uncovered, and adds only a host-based IDS which is detection-only rather than prevention.

CAnti-malware/virus/spyware/spam software, as well as a host based firewall and biometric

Choice C replaces strong multi-factor authentication with biometric authentication alone, which is a single authentication factor and provides incomplete access control coverage.

DAnti-malware/spam software, as well as a host based firewall and strong, three-factor

Choice D omits anti-virus and anti-spyware from its protection list, leaving significant threat vectors unaddressed on the server endpoint.

Concept tested: Comprehensive endpoint security software components for servers

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-128.pdf

Topics

#endpoint security#host-based security#anti-malware#defense-in-depth

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice