nerdexam
CompTIA

CAS-003 · Question #298

A company's existing forward proxies support software-based TLS decryption, but are currently at 60% load just dealing with AV scanning and content analysis for HTTP traffic. More than 70% outbound…

The correct answer is A. Purchase the SSL, decryption license for the firewalls and route traffic back to the proxies for end-. Purchasing SSL/TLS decryption licenses for the firewalls and routing decrypted traffic back to the existing proxies for inspection is the best solution. The firewalls are only at 30% load and have dormant decryption modules - activating them offloads the cryptographic work from…

Enterprise Security Architecture

Question

A company's existing forward proxies support software-based TLS decryption, but are currently at 60% load just dealing with AV scanning and content analysis for HTTP traffic. More than 70% outbound web traffic is currently encrypted. The switching and routing network infrastructure precludes adding capacity, preventing the installation of a dedicated TLS decryption system. The network firewall infrastructure is currently at 30% load and has software decryption modules that can be activated by purchasing additional license keys. An existing project is rolling out agent updates to end-user desktops as part of an endpoint security refresh. Which of the following is the BEST way to address these issues and mitigate risks to the organization?

Options

  • APurchase the SSL, decryption license for the firewalls and route traffic back to the proxies for end-
  • BRoll out application whitelisting to end-user desktops and decommission the existing proxies,
  • CUse an EDP solution to address the malware issue and accept the diminishing role of the proxy
  • DAccept the current risk and seek possible funding approval in the next budget cycle to replace the

How the community answered

(26 responses)
  • A
    65% (17)
  • B
    19% (5)
  • C
    8% (2)
  • D
    8% (2)

Explanation

Purchasing SSL/TLS decryption licenses for the firewalls and routing decrypted traffic back to the existing proxies for inspection is the best solution. The firewalls are only at 30% load and have dormant decryption modules - activating them offloads the cryptographic work from the forward proxies, which are overloaded at 60% handling AV scanning and content analysis. This resolves the capacity problem without adding new hardware (which is blocked by the network infrastructure constraint). Option B (application whitelisting and decommissioning proxies) eliminates existing security controls. Option C (relying solely on endpoint detection) removes network-layer visibility. Option D (accepting risk) is not appropriate given that 70% of outbound traffic is unscrutinized.

Topics

#TLS inspection#network capacity planning#SSL decryption#proxy architecture

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice