CompTIA SecurityX Certification Exam CAS-005 Question # 37 Topic 4 Discussion

CompTIA SecurityX Certification Exam CAS-005 Question # 37 Topic 4 Discussion

CAS-005 Exam Topic 4 Question 37 Discussion:
Question #: 37
Topic #: 4

During a recentsecurity event, access from thenon-production environment to the production environmentenabledunauthorized usersto:

Installunapproved software

Makeunplanned configuration changes

During theinvestigation, the following findings were identified:

Several new users were added in bulkby theIAM team

Additionalfirewalls and routerswere recently added

Vulnerability assessmentshave been disabled formore than 30 days

Theapplication allow listhas not been modified intwo weeks

Logs were unavailablefor various types of traffic

Endpoints have not been patchedinover ten days

Which of the following actions would most likely need to be taken toensure proper monitoring?(Select two)


A.

Disable bulk user creationsby the IAM team


B.

Extend log retention for all security and network devices to180 daysfor all traffic


C.

Review the application allow listdaily


D.

Routinely update allendpoints and network devicesas soon as new patches/hot fixes are available


E.

Ensure allnetwork and security devicesare sending relevant data to theSIEM


F.

Configure firewall rules toonly allow production-to-non-productiontraffic


Get Premium CAS-005 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.