nerdexam
CompTIA

CAS-005 · Question #363

A security analyst identified a vulnerable and deprecated runtime engine that Is supporting a public-facing banking application. The developers anticipate the transition to modern development…

The correct answer is D. Configuring IPS and WAF with signatures. To mitigate the risk of the vulnerable and deprecated runtime engine while the developers transition to a more modern environment, configuring an Intrusion Prevention System (IPS) and a Web Application Firewall (WAF) with appropriate signatures would provide protection without…

Submitted by yasin.bd· Mar 6, 2026Security Operations

Question

A security analyst identified a vulnerable and deprecated runtime engine that Is supporting a public-facing banking application. The developers anticipate the transition to modern development environments will take at least a month. Which of the following controls would best mitigate the risk without interrupting the service during the transition?

Options

  • AShutting down the systems until the code is ready
  • BUninstalling the impacted runtime engine
  • CSelectively blocking traffic on the affected port
  • DConfiguring IPS and WAF with signatures

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    14% (3)
  • C
    5% (1)
  • D
    73% (16)

Explanation

To mitigate the risk of the vulnerable and deprecated runtime engine while the developers transition to a more modern environment, configuring an Intrusion Prevention System (IPS) and a Web Application Firewall (WAF) with appropriate signatures would provide protection without disrupting the service. These security controls can help detect and block known exploits targeting the vulnerable runtime engine. By applying these measures, the application can continue running while minimizing the risk of exploitation from external threats.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice