CAS-003 · Question #617
A company recently migrated to a SaaS-based email solution. The solution is configured as follows. - Passwords are synced to the cloud to allow for SSO - Cloud-based antivirus is enabled…
The correct answer is B. Implement a third-party CASB solution. E. Install a virtual SIEM within the email cloud provider. The core problem is insufficient, delayed visibility into the SaaS email environment. A CASB (Cloud Access Security Broker) - option B - sits between users and cloud services, providing real-time behavioral analytics and alerting on anomalous activity such as impossible-travel…
Question
A company recently migrated to a SaaS-based email solution. The solution is configured as follows.
- Passwords are synced to the cloud to allow for SSO
- Cloud-based antivirus is enabled
- Cloud-based anti-spam is enabled
- Subscription-based blacklist is enabled
Although the above controls are enabled, the company's security administrator is unable to detect an account compromise caused by phishing attacks in a timely fashion because email logs are not immediately available to review. Which of the following would allow the company to gam additional visibility and reduce additional costs? (Select TWO)
Options
- AMigrate the email antivirus and anti-spam on-premises
- BImplement a third-party CASB solution.
- CDisable the current SSO model and enable federation
- DFeed the attacker IPs from the company IDS into the email blacklist
- EInstall a virtual SIEM within the email cloud provider
- FAdd email servers to NOC monitoring
How the community answered
(57 responses)- A4% (2)
- B54% (31)
- C21% (12)
- D14% (8)
- F7% (4)
Explanation
The core problem is insufficient, delayed visibility into the SaaS email environment. A CASB (Cloud Access Security Broker) - option B - sits between users and cloud services, providing real-time behavioral analytics and alerting on anomalous activity such as impossible-travel logins or mass email forwarding characteristic of account compromise, without requiring on-premises infrastructure. A virtual SIEM deployed within the cloud provider's environment - option E - aggregates email logs natively, making them immediately queryable and enabling timely incident detection. Together these add visibility while avoiding the cost of migrating services on-premises (A) or duplicating existing controls. Options C, D, and F do not address the log-availability or detection-timeliness problem.
Topics
Community Discussion
No community discussion yet for this question.