nerdexam
CompTIA

CAS-002 · Question #621

An IT administrator has been tasked by the Chief Executive Officer with implementing security using a single device based on the following requirements: 1. Selective sandboxing of suspicious code to…

The correct answer is A. UTM. A UTM appliance is the only single device that natively combines sandbox analysis, VoIP application-layer gateway support, and application control in one platform.

Technical Integration of Enterprise Components

Question

An IT administrator has been tasked by the Chief Executive Officer with implementing security using a single device based on the following requirements: 1. Selective sandboxing of suspicious code to determine malicious intent. 2. VoIP handling for SIP and H.323 connections. 3. Block potentially unwanted applications. Which of the following devices would BEST meet all of these requirements?

Options

  • AUTM
  • BHIDS
  • CNIDS
  • DWAF
  • EHSM

How the community answered

(36 responses)
  • A
    72% (26)
  • B
    8% (3)
  • C
    14% (5)
  • D
    3% (1)
  • E
    3% (1)

Why each option

A UTM appliance is the only single device that natively combines sandbox analysis, VoIP application-layer gateway support, and application control in one platform.

AUTMCorrect

A Unified Threat Management device integrates multiple distinct security engines into a single appliance, including behavioral sandboxing that executes suspicious code in an isolated environment to determine malicious intent, VoIP application-layer gateways that inspect and manage SIP and H.323 signaling, and application control policies that identify and block potentially unwanted applications. No other device listed covers all three requirements from a single unit.

BHIDS

A Host-based Intrusion Detection System runs on individual endpoints and has no capability to inspect or manage network-level VoIP signaling protocols such as SIP or H.323.

CNIDS

A Network Intrusion Detection System is a passive monitoring device that detects anomalies but cannot sandbox code, handle VoIP call control, or actively block unwanted applications.

DWAF

A Web Application Firewall is scoped exclusively to HTTP and HTTPS traffic for web application protection and provides none of the sandboxing, VoIP handling, or broad application blocking functions required.

EHSM

A Hardware Security Module is a dedicated cryptographic processor for key management and digital signing operations and has no relevance to sandboxing, VoIP inspection, or application filtering.

Concept tested: UTM device multi-function security capabilities

Source: https://www.fortinet.com/resources/cyberglossary/unified-threat-management

Topics

#UTM#unified threat management#sandboxing#VoIP security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice