nerdexam
CompTIA

CAS-002 · Question #627

A security administrator notices a recent increase in workstations becoming compromised by malware. Often, the malware is delivered via drive-by downloads, from malware hosting websites, and is not…

The correct answer is B. Deploy a cloud-based content filter and enable the appropriate category to prevent further. Drive-by download attacks from malicious websites are best mitigated by blocking access to those sites at the network level before any content reaches the workstation.

Enterprise Security

Question

A security administrator notices a recent increase in workstations becoming compromised by malware. Often, the malware is delivered via drive-by downloads, from malware hosting websites, and is not being detected by the corporate antivirus. Which of the following solutions would provide the BEST protection for the company?

Options

  • AIncrease the frequency of antivirus downloads and install updates to all workstations.
  • BDeploy a cloud-based content filter and enable the appropriate category to prevent further
  • CDeploy a NIPS to inspect and block all web traffic which may contain malware and exploits.
  • DDeploy a web based gateway antivirus server to intercept viruses before they enter the

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    76% (22)
  • C
    7% (2)
  • D
    14% (4)

Why each option

Drive-by download attacks from malicious websites are best mitigated by blocking access to those sites at the network level before any content reaches the workstation.

AIncrease the frequency of antivirus downloads and install updates to all workstations.

Increasing antivirus update frequency does not help when the malware is unknown or zero-day and is already evading the existing AV engine's signatures.

BDeploy a cloud-based content filter and enable the appropriate category to prevent furtherCorrect

A cloud-based content filter blocks access to known malware-hosting websites by category before any payload is delivered to the endpoint, bypassing the antivirus detection gap entirely. This is a proactive defense that stops the attack at the source rather than attempting to detect malware after it arrives. Because the malicious content never reaches the workstation, signature-based AV failures become irrelevant.

CDeploy a NIPS to inspect and block all web traffic which may contain malware and exploits.

A NIPS still relies on detection of known exploit signatures rather than preventing access to malicious sites, and may not intercept all web-based malware especially over encrypted channels.

DDeploy a web based gateway antivirus server to intercept viruses before they enter the

A gateway antivirus server uses the same signature-based detection that is already failing, so it would not solve the problem of malware evading corporate antivirus.

Concept tested: Web content filtering to block malicious websites

Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/malware

Topics

#content filtering#drive-by downloads#malware prevention#web security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice