CAS-003 · Question #308
The legal department has required that all traffic to and from a company's cloud-based word processing and email system is logged. To meet this requirement, the Chief Information Security Officer…
The correct answer is A. Confidential or sensitive documents are inspected by the firewall before being logged. A next-generation firewall performing SSL/TLS inspection (also called SSL bumping or HTTPS inspection) acts as a man-in-the-middle: it decrypts encrypted traffic, inspects the content, then re-encrypts it. This means that confidential documents being created or emailed through…
Question
The legal department has required that all traffic to and from a company's cloud-based word processing and email system is logged. To meet this requirement, the Chief Information Security Officer (CISO) has implemented a next-generation firewall to perform inspection of the secure traffic and has decided to use a cloud-based log aggregation solution for all traffic that is logged. Which of the following presents a long-term risk to user privacy in this scenario?
Options
- AConfidential or sensitive documents are inspected by the firewall before being logged.
- BLatency when viewing videos and other online content may increase.
- CReports generated from the firewall will take longer to produce due to more information from
- DStored logs may contain non-encrypted usernames and passwords for personal websites.
How the community answered
(46 responses)- A59% (27)
- B24% (11)
- C11% (5)
- D7% (3)
Explanation
A next-generation firewall performing SSL/TLS inspection (also called SSL bumping or HTTPS inspection) acts as a man-in-the-middle: it decrypts encrypted traffic, inspects the content, then re-encrypts it. This means that confidential documents being created or emailed through the cloud-based system pass through the firewall in plaintext before being logged. Over time, these logs will accumulate sensitive and confidential organizational data stored in an external cloud log aggregation service-creating a long-term and growing privacy risk. Option D (usernames/passwords in logs) is a real concern but is more of a point-in-time risk than a compounding long-term one. Options B and C describe performance issues, not privacy risks.
Topics
Community Discussion
No community discussion yet for this question.