A company implements an Al model that handles sensitive and personally identifiable information. Which of the following threats is most likely the company's primary concern?
A security architect is mitigating a vulnerability that previously led to a web application data breach. An analysis into the root cause of the issue finds the following:
An administrator's account was hijacked and used on several Autonomous System Numbers within 30 minutes.
All administrators use named accounts that require multifactor authentication.
Single sign-on is used for all company applications.Which of the following should the security architect do to mitigate the issue?
The hijacked administrator account was used across multiple ASNs (indicating different network locations) in a short time, despite MFA and SSO. This suggests a stolen session or token misuse. Let's analyze:
A . Token theft detection with lockouts:Useful for detecting stolen SSO tokens, but it's reactive and may not prevent initial misuse across networks.
B . Context-based authentication:This adds real-time checks (e.g., geolocation, IP changes) to verify login attempts. Given the rapid ASN changes, this proactively mitigates the issue by challenging suspicious logins, aligning with CAS-005's focus on adaptive security.
C . Decentralize accounts:This removes SSO, increasing complexity and weakening MFA enforcement, which isn't practical or secure.
A cybersecurity architect is reviewing the detection and monitoring capabilities for a global company that recently made multiple acquisitions. The architect discovers that the acquired companies use different vendors for detection and monitoring The architect's goal is to:
* Create a collection of use cases to help detect known threats
* Include those use cases in a centralized library for use across all of the companies
Which of the following is the best way to achieve this goal?
To create a collection of use cases for detecting known threats and include them in a centralized library for use across multiple companies withdifferent vendors, Sigma rules are the best option. Here's why:
Centralized Rule Management: By using Sigma rules, the cybersecurity architect can create a centralized library of detection rules that can be easily shared and implemented across different detection and monitoring systems used by the acquired companies. This ensures consistency in threat detection capabilities.
Ease of Use and Flexibility: Sigma provides a structured and straightforward format for defining detection logic. It allows for the easy creation, modification, and sharing of rules, facilitating collaboration and standardization across the organization.
An organization mat performs real-time financial processing is implementing a new backup solution Given the following business requirements?
* The backup solution must reduce the risk for potential backup compromise
* The backup solution must be resilient to a ransomware attack.
* The time to restore from backups is less important than the backup data integrity
* Multiple copies of production data must be maintained
Which of the following backup strategies best meets these requirement?
A .Creating a secondary, immutable storage array and updating it with live data on a continuous basis: An immutable storage array ensures that data, once written, cannot be altered or deleted. This greatly reduces the risk of backup compromise and provides resilience against ransomware attacks, as the ransomware cannot modify or delete the backup data. Maintaining multiple copies of production data with an immutable storage solution ensures data integrity and compliance with the requirement for multiple copies.
Other options:
B . Utilizing two connected storage arrays and ensuring the arrays constantly sync: While this ensures data redundancy, it does not provide protection against ransomware attacks, as both arrays could be compromised simultaneously.
C . Enabling remote journaling on the databases: This ensures real-time transaction mirroring but does not address the requirement for reducing the risk of backup compromise or resilience to ransomware.
D . Setting up anti-tampering on the databases: While this helps ensure data integrity, it does not provide a comprehensive backup solution that meets all the specified requirements.
CompTIA Security+ Study Guide
NIST SP 800-209, 'Security Guidelines for Storage Infrastructure'
'Immutable Backup Architecture' by Veeam
Which of the following are risks associated with vendor lock-in? (Select two).
Option B:Vendors changing offerings (e.g., features, pricing) can disrupt the client, a key lock-in risk.
Option D:Decreased quality of service may result from reliance on a single vendor without alternatives.
Option A:Seamless data movement is a benefit, not a risk.
Option C:Sufficient service is neutral or positive, not a risk.
Option E:Multicloud is hindered by lock-in, not a risk of it.
Option F:Increased interoperability contradicts lock-in's limitations.
Brian White
6 days agoLisa Murphy
18 days agoKimberly Garcia
26 days agoJessica Nguyen
1 month agoJustin Morgan
2 months agoAnthony Phillips
2 months agoGary King
2 months agoJason Roberts
3 months agoMichael Martinez
3 months agoThomas Morgan
3 months agoAngela Turner
3 months agoJustin Flores
3 months agoPaul Evans
3 months agoRachel Nguyen
3 months agoDorothy Turner
3 months agoPauline
4 months agoMarsha
4 months agoBelen
5 months agoLashaunda
5 months agoOlga
5 months agoMichal
5 months agoPok
6 months agoVanda
6 months agoShawnta
6 months agoLeatha
6 months agoAn
7 months agoDesirae
7 months agoGayla
7 months agoCecil
7 months agoLino
8 months agoHildred
8 months agoArthur
8 months agoJose
8 months agoIzetta
9 months agoCassie
9 months agoSol
9 months agoBeatriz
10 months agoLeigha
10 months agoLarae
10 months agoJesus
10 months agoTu
11 months agoGilma
11 months agoPhillip
11 months agoRolf
11 months agoMargart
1 year agoStanford
1 year agoRessie
1 year agoMillie
1 year agoLouis
1 year agoJacqueline
2 years agoMaryann
2 years agoNobuko
2 years agoOzell
2 years agoSanda
2 years agoViola
2 years agoPortia
2 years agoKristel
2 years agoBrandon
2 years agoLouvenia
2 years ago