nerdexam
CompTIA

CAS-002 · Question #624

An administrator's company has recently had to reduce the number of Tier 3 help desk technicians available to support enterprise service requests. As a result, configuration standards have declined…

The correct answer is B. Disable command execution G. BIOS security I. IdM. To prevent an authorized user from conducting internal reconnaissance, organizations should restrict command execution, harden BIOS settings, and enforce identity management controls.

Enterprise Security

Question

An administrator's company has recently had to reduce the number of Tier 3 help desk technicians available to support enterprise service requests. As a result, configuration standards have declined as administrators develop scripts to troubleshoot and fix customer issues. The administrator has observed that several default configurations have not been fixed through applied group policy or configured in the baseline. Which of the following are controls the administrator should recommend to the organization's security manager to prevent an authorized user from conducting internal reconnaissance on the organization's network? (Select THREE).

Options

  • ANetwork file system
  • BDisable command execution
  • CPort security
  • DTLS
  • ESearch engine reconnaissance
  • FNIDS
  • GBIOS security
  • HHIDS
  • IIdM

How the community answered

(34 responses)
  • A
    29% (10)
  • B
    41% (14)
  • C
    3% (1)
  • D
    6% (2)
  • E
    3% (1)
  • H
    18% (6)

Why each option

To prevent an authorized user from conducting internal reconnaissance, organizations should restrict command execution, harden BIOS settings, and enforce identity management controls.

ANetwork file system

Network File System is a file sharing protocol, not a control that limits reconnaissance capability.

BDisable command executionCorrect

Disabling command execution prevents users from running reconnaissance tools such as netstat, ipconfig, or nmap that reveal network topology and open ports.

CPort security

Port security controls which physical devices connect to switch ports and does not restrict what an already-connected authorized user can do on the network.

DTLS

TLS encrypts data in transit but does not prevent an authorized user from querying network resources or running enumeration commands.

ESearch engine reconnaissance

Search engine reconnaissance is an attack technique, not a security control.

FNIDS

NIDS detects suspicious network activity but does not actively prevent an authorized user from performing reconnaissance.

GBIOS securityCorrect

BIOS security prevents attackers from booting to external media or altering system startup configurations that could bypass OS-level restrictions.

HHIDS

HIDS detects unauthorized changes or suspicious activity on a host but does not proactively prevent a user from running reconnaissance commands.

IIdMCorrect

Identity Management (IdM) enforces least-privilege access, ensuring users can only access resources necessary for their role, limiting lateral movement and information gathering.

Concept tested: Controls preventing internal network reconnaissance

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

Topics

#internal reconnaissance#identity management#BIOS security#configuration hardening

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice