CAS-003 Exam Question 86

A company's security policy states any remote connections must be validated using two forms of network-based authentication. It also states local administrative accounts should not be used for any remote access. PKI currently is not configured within the network. RSA tokens have been provided to all employees, as well as a mobile application that can be used for 2FA authentication. A new NGFW has been installed within the network to provide security for external connections, and the company has decided to use it for VPN connections as well. Which of the following should be configured? (Choose two.)
  • CAS-003 Exam Question 87

    A cybersecurity analyst has received an alert that well-known "call home" messages are continuously observed by network sensors at the network boundary. The proxy firewall successfully drops the massages. After determining the alert was a true positive, which of the following represents OST likely cause?
  • CAS-003 Exam Question 88

    Ann, a Physical Security Manager, is ready to replace all 50 analog surveillance cameras with IP cameras with built-in web management.
    Ann has several security guard desks on different networks that must be able to view the cameras without unauthorized people viewing the video as well.
    The selected IP camera vendor does not have the ability to authenticate users at the camera level.
    Which of the following should Ann suggest to BEST secure this environment?
  • CAS-003 Exam Question 89

    When of the following is the BEST reason to implement a separation of duties policy?
  • CAS-003 Exam Question 90

    Ann is testing the robustness of a marketing website through an intercepting proxy. She has intercepted the following HTTP request:
    POST /login.aspx HTTP/1.1
    Host: comptia.org
    Content-type: text/html
    txtUsername=ann&txtPassword=ann&alreadyLoggedIn=false&submit=true
    Which of the following should Ann perform to test whether the website is susceptible to a simple authentication bypass?