nerdexam
CompTIA

CAS-003 · Question #617

A company recently migrated to a SaaS-based email solution. The solution is configured as follows. - Passwords are synced to the cloud to allow for SSO - Cloud-based antivirus is enabled…

The correct answer is B. Implement a third-party CASB solution. E. Install a virtual SIEM within the email cloud provider. The core problem is insufficient, delayed visibility into the SaaS email environment. A CASB (Cloud Access Security Broker) - option B - sits between users and cloud services, providing real-time behavioral analytics and alerting on anomalous activity such as impossible-travel…

Enterprise Security Operations

Question

A company recently migrated to a SaaS-based email solution. The solution is configured as follows.

  • Passwords are synced to the cloud to allow for SSO
  • Cloud-based antivirus is enabled
  • Cloud-based anti-spam is enabled
  • Subscription-based blacklist is enabled

Although the above controls are enabled, the company's security administrator is unable to detect an account compromise caused by phishing attacks in a timely fashion because email logs are not immediately available to review. Which of the following would allow the company to gam additional visibility and reduce additional costs? (Select TWO)

Options

  • AMigrate the email antivirus and anti-spam on-premises
  • BImplement a third-party CASB solution.
  • CDisable the current SSO model and enable federation
  • DFeed the attacker IPs from the company IDS into the email blacklist
  • EInstall a virtual SIEM within the email cloud provider
  • FAdd email servers to NOC monitoring

How the community answered

(57 responses)
  • A
    4% (2)
  • B
    54% (31)
  • C
    21% (12)
  • D
    14% (8)
  • F
    7% (4)

Explanation

The core problem is insufficient, delayed visibility into the SaaS email environment. A CASB (Cloud Access Security Broker) - option B - sits between users and cloud services, providing real-time behavioral analytics and alerting on anomalous activity such as impossible-travel logins or mass email forwarding characteristic of account compromise, without requiring on-premises infrastructure. A virtual SIEM deployed within the cloud provider's environment - option E - aggregates email logs natively, making them immediately queryable and enabling timely incident detection. Together these add visibility while avoiding the cost of migrating services on-premises (A) or duplicating existing controls. Options C, D, and F do not address the log-availability or detection-timeliness problem.

Topics

#CASB#SIEM#cloud email security#visibility

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice