nerdexam
CompTIA

CAS-003 · Question #623

A company's Internet connection is commonly saturated during business hours, affecting Internet availability. The company requires all Internet traffic to be business related. After analyzing the…

The correct answer is A. Block outbound SSL traffic to prevent data exfiltration. The corporate policy mandates that all Internet traffic must be business-related. The analysis reveals the connection is dominated by SSL traffic resolving to CDNs - which commonly serve personal content such as streaming media, social platforms, and consumer software. Since…

Enterprise Security Operations

Question

A company's Internet connection is commonly saturated during business hours, affecting Internet availability. The company requires all Internet traffic to be business related. After analyzing the traffic over a period of a few hours, the security administrator observes the following:

The majority of the IP addresses associated with the TCP/SSL traffic resolve to CDNs. Which of the following should the administrator recommend for the CDN traffic to meet the corporate security requirements?

Exhibit

CAS-003 question #623 exhibit

Options

  • ABlock outbound SSL traffic to prevent data exfiltration.
  • BConfirm the use of the CDN by monitoring NetFlow data
  • CFurther investigate the traffic using a sanctioned MITM proxy.
  • DImplement an IPS to drop packets associated with the CDN.

How the community answered

(52 responses)
  • A
    67% (35)
  • B
    19% (10)
  • C
    4% (2)
  • D
    10% (5)

Explanation

The corporate policy mandates that all Internet traffic must be business-related. The analysis reveals the connection is dominated by SSL traffic resolving to CDNs - which commonly serve personal content such as streaming media, social platforms, and consumer software. Since the content inside SSL tunnels cannot be inspected without a proxy, and the policy requires all traffic to be business-related, blocking outbound SSL to non-business CDNs (A) directly enforces the policy and frees saturated bandwidth. Option B (NetFlow monitoring) only confirms CDN use without enforcing the policy. Option C (MITM proxy) would allow content inspection, but the question asks what recommendation meets the stated corporate requirement immediately. Option D (IPS dropping CDN packets) is less targeted and would affect legitimate business CDN usage.

Topics

#SSL inspection#CDN traffic#traffic analysis#DLP

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice