nerdexam
CompTIA

CAS-003 · Question #427

A technician is validating compliance with organizational policies. The user and machine accounts in the AD are not set to expire, which is non-compliant. Which of the following network tools would…

The correct answer is C. SCAP scanner. SIEM is a logging which I guess could find this but I don’t think this is the right answer since this doesnt indicate it was a change made by anyone and I don’t think a logging tool would just pull that information without reason. IDS does not monitor this. This is not a part…

Enterprise Security Operations

Question

A technician is validating compliance with organizational policies. The user and machine accounts in the AD are not set to expire, which is non-compliant. Which of the following network tools would provide this type of information?

Options

  • ASIEM server
  • BIDS appliance
  • CSCAP scanner
  • DHTTP interceptor

How the community answered

(15 responses)
  • B
    7% (1)
  • C
    87% (13)
  • D
    7% (1)

Explanation

SIEM is a logging which I guess could find this but I don’t think this is the right answer since this doesnt indicate it was a change made by anyone and I don’t think a logging tool would just pull that information without reason. IDS does not monitor this. This is not a part of what an IDS does. HTTP interceptor is completely irrelevant to this question.

Topics

#SCAP#compliance scanning#Active Directory#account expiration

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice