CAS-005 · Question #161
A security architect is onboarding a new EDR agent on servers that traditionally do not have internet access. In order for the agent to receive updates and report back to the management console…
The correct answer is A. Create a firewall rule to only allow traffic from the subnet to the internet via a proxy. C. Configure a proxy policy that allows only fully qualified domain names needed to communicate to. Create a firewall rule to only allow traffic from the subnet to the internet via a proxy ensures that the servers can connect to the internet through a controlled channel, allowing the EDR agent to get updates and report back securely. Configure a proxy policy that allows only…
Question
A security architect is onboarding a new EDR agent on servers that traditionally do not have internet access. In order for the agent to receive updates and report back to the management console, some changes must be made. Which of the following should the architect do to best accomplish this requirement? (Choose two.)
Options
- ACreate a firewall rule to only allow traffic from the subnet to the internet via a proxy.
- BConfigure a proxy policy that blocks all traffic on port 443.
- CConfigure a proxy policy that allows only fully qualified domain names needed to communicate to
- DCreate a firewall rule to only allow traffic from the subnet to the internet via port 443.
- ECreate a firewall rule to only allow traffic from the subnet to the internet to fully qualified names
- FConfigure a proxy policy that blocks only lists of known-bad, fully qualified domain names.
How the community answered
(34 responses)- A71% (24)
- B15% (5)
- D3% (1)
- E3% (1)
- F9% (3)
Explanation
Create a firewall rule to only allow traffic from the subnet to the internet via a proxy ensures that the servers can connect to the internet through a controlled channel, allowing the EDR agent to get updates and report back securely. Configure a proxy policy that allows only fully qualified domain names needed to communicate to a portal ensures that the agent can reach only the necessary services for updates and reporting, minimizing exposure and enhancing security by limiting access to only trusted domains.
Community Discussion
No community discussion yet for this question.