nerdexam
CompTIA

CAS-002 · Question #722

A network administrator with a company's NSP has received a CERT alert for targeted adversarial behavior at the company. In addition to the company's physical security, which of the following can…

The correct answer is D. HIDS E. Port scanner. To detect a malicious actor physically accessing the network from within, administrators should use tools that monitor host activity and enumerate active network connections.

Technical Integration of Enterprise Components

Question

A network administrator with a company's NSP has received a CERT alert for targeted adversarial behavior at the company. In addition to the company's physical security, which of the following can the network administrator use to scan and detect the presence of a malicious actor physically accessing the company's network or information systems from within? (Select TWO).

Options

  • ARAS
  • BVulnerability scanner
  • CHTTP intercept
  • DHIDS
  • EPort scanner
  • FProtocol analyzer

How the community answered

(53 responses)
  • C
    2% (1)
  • D
    94% (50)
  • F
    4% (2)

Why each option

To detect a malicious actor physically accessing the network from within, administrators should use tools that monitor host activity and enumerate active network connections.

ARAS

RAS (Remote Access Service) provides remote connectivity to a network but has no detection or scanning capability for identifying malicious actors already present on the internal network.

BVulnerability scanner

A vulnerability scanner identifies software weaknesses and misconfigurations in systems but does not detect the active presence or behavior of a malicious actor on the network.

CHTTP intercept

HTTP intercept captures and inspects web traffic but is limited to HTTP sessions and cannot detect a physically present intruder accessing non-web resources or internal systems.

DHIDSCorrect

A Host-based Intrusion Detection System (HIDS) monitors activity directly on individual hosts, alerting administrators to unauthorized access attempts, file changes, or suspicious processes that an internal threat actor might trigger on a system they have physically accessed.

EPort scannerCorrect

A port scanner can enumerate open ports and active services on internal network devices, helping detect unauthorized devices or rogue connections introduced by an intruder who has gained physical access to the network.

FProtocol analyzer

A protocol analyzer passively captures and decodes network traffic and requires manual human analysis to identify threats, so it does not actively scan for or alert on a malicious actor's presence.

Concept tested: Insider threat detection using HIDS and port scanning

Source: https://csrc.nist.gov/glossary/term/host_based_intrusion_detection_system

Topics

#HIDS#port scanning#intrusion detection#physical breach detection

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice