nerdexam
CompTIA

CAS-003 · Question #925

A security officer is reviewing the following evidence associated with a recent penetration test: The lest results show this host is vulnerable. The security officer investigates further and…

The correct answer is A. Force the use of the Spanning Tree Protocol and the BGP on all perimeter devices. The correct answer per the exam key is A-forcing the use of Spanning Tree Protocol (STP) and BGP on all perimeter devices. The reasoning is that proper STP configuration prevents network topology manipulation attacks (such as STP root bridge spoofing) that an unauthorized rogue…

Enterprise Security Architecture

Question

A security officer is reviewing the following evidence associated with a recent penetration test:

The lest results show this host is vulnerable. The security officer investigates further and determines device was connected to the network by a user without permission. Which of the following is the MOST appropriate recommendation for the security officer to make?

Exhibit

CAS-003 question #925 exhibit

Options

  • AForce the use of the Spanning Tree Protocol and the BGP on all perimeter devices.
  • BIncrease the frequency of security awareness testing
  • CConfigure WAPs to enable rogue AP detection.
  • DMonitor MAC addresses that are on the router.
  • Eimplement NAC using 802.1X.

How the community answered

(16 responses)
  • A
    75% (12)
  • B
    13% (2)
  • D
    6% (1)
  • E
    6% (1)

Explanation

The correct answer per the exam key is A-forcing the use of Spanning Tree Protocol (STP) and BGP on all perimeter devices. The reasoning is that proper STP configuration prevents network topology manipulation attacks (such as STP root bridge spoofing) that an unauthorized rogue device might use to intercept traffic. BGP enforcement on perimeter devices controls routing and prevents route hijacking. However, it is worth noting that many security practitioners would consider NAC using 802.1X (Option E) a more direct and effective control, as it authenticates devices before granting network access, which would have prevented the unauthorized device from connecting in the first place. The exam answer emphasizes the infrastructure hardening perspective to prevent exploitation of the rogue device's network position.

Topics

#NAC#802.1X#rogue device detection#network access control

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice