Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CV0-004 Exam - Topic 1 Question 49 Discussion

A customer relationship management application, which is hosted in a public cloud laaS network, is vulnerable to a remote command execution vulnerability. Which of the following isthe best solution for the security engineer to implement to prevent the application from being exploited by basic attacks?
D) WAF
A) IPS
B) ACL
C) DLP

CompTIA CV0-004 Exam - Topic 1 Question 49 Discussion

Actual exam question for CompTIA's CV0-004 exam
Question #: 49
Topic #: 1
[All CV0-004 Questions]

A customer relationship management application, which is hosted in a public cloud laaS network, is vulnerable to a remote command execution vulnerability. Which of the following is

the best solution for the security engineer to implement to prevent the application from being exploited by basic attacks?

Show Suggested Answer Hide Answer
Suggested Answer: D

A Web Application Firewall (WAF) is the best solution to implement for a public cloud IaaS hosted customer relationship management application vulnerable to remote command execution attacks. WAFs are designed to monitor, filter, and block malicious HTTP/S traffic to and from a web application to protect against various application layer attacks, including remote command execution. References: CompTIA Cloud+ Study Guide (Exam CV0-004) - Chapter on Security in the Cloud


Contribute your Thoughts:

0/2000 characters
Eura
3 hours ago
I lean towards WAF as the best option since it specifically targets web application attacks, but I need to double-check my notes on that.
upvoted 0 times
...
Kenny
5 days ago
ACLs seem like they could limit access, but I doubt they would directly prevent exploitation of that vulnerability.
upvoted 0 times
...
Idella
10 days ago
I practiced a similar question where an IPS was the answer, but I feel like that might not be enough for remote command execution.
upvoted 0 times
...
Vallie
16 days ago
I think I remember that a WAF could help filter out malicious requests, but I'm not entirely sure if it's the best choice here.
upvoted 0 times
...

Save Cancel