CAS-003 · Question #883
A large organization suffers a data breach after one staff member inadvertently shares a document on a corporate-approved, file-sharing, cloud-collaboration service. The security administrator must…
The correct answer is A. Implement dedicated SSL decryptors for outbound HTTPS connections. C. Block webmail and file-sharing categories on the proxies. E. Deploy a DLP solution that scans FTP and HTTPS/HTTP content. The breach occurred via a corporate-approved cloud file-sharing service, so controls must address both prevention and early detection: (A) Dedicated SSL/TLS decryptors allow deep inspection of encrypted HTTPS traffic flowing through the on-premises proxies, enabling content…
Question
Options
- AImplement dedicated SSL decryptors for outbound HTTPS connections.
- BMigrate all staff to cloud-based proxy services.
- CBlock webmail and file-sharing categories on the proxies.
- DDeploy a CASB solution to monitor and restrict file-sharing cloud services.
- EDeploy a DLP solution that scans FTP and HTTPS/HTTP content.
- FInstall an on-premises file-sharing service that can be accessed only when on the corporate
- GDeploy VPN software and have all remote staff connect to the Internet via the corporate proxies.
- HConfigure the SIEM to alert on access to all external collaboration sites.
How the community answered
(41 responses)- A56% (23)
- B10% (4)
- D2% (1)
- F5% (2)
- G24% (10)
- H2% (1)
Explanation
The breach occurred via a corporate-approved cloud file-sharing service, so controls must address both prevention and early detection: (A) Dedicated SSL/TLS decryptors allow deep inspection of encrypted HTTPS traffic flowing through the on-premises proxies, enabling content visibility into what is being uploaded to cloud services. (C) Blocking unauthorized webmail and file-sharing categories on proxies reduces the attack surface by limiting channels employees can use, while the approved service remains accessible under policy. (E) A DLP (Data Loss Prevention) solution scanning FTP and HTTPS/HTTP content can detect sensitive data in outbound streams and alert or block transmission. Note: A CASB (Option D) is often considered the most targeted solution for this scenario, as it specifically monitors cloud service usage and can enforce policies on the approved service itself. If the exam intends D and E as the answer, that is also technically defensible. The combination of traffic decryption, channel restriction, and content scanning provides the layered defense the question requires.
Topics
Community Discussion
No community discussion yet for this question.