An organization mat performs real-time financial processing is implementing a new backup solution Given the following business requirements?
* The backup solution must reduce the risk for potential backup compromise
* The backup solution must be resilient to a ransomware attack.
* The time to restore from backups is less important than the backup data integrity
* Multiple copies of production data must be maintained
Which of the following backup strategies best meets these requirement?
A .Creating a secondary, immutable storage array and updating it with live data on a continuous basis: An immutable storage array ensures that data, once written, cannot be altered or deleted. This greatly reduces the risk of backup compromise and provides resilience against ransomware attacks, as the ransomware cannot modify or delete the backup data. Maintaining multiple copies of production data with an immutable storage solution ensures data integrity and compliance with the requirement for multiple copies.
Other options:
B . Utilizing two connected storage arrays and ensuring the arrays constantly sync: While this ensures data redundancy, it does not provide protection against ransomware attacks, as both arrays could be compromised simultaneously.
C . Enabling remote journaling on the databases: This ensures real-time transaction mirroring but does not address the requirement for reducing the risk of backup compromise or resilience to ransomware.
D . Setting up anti-tampering on the databases: While this helps ensure data integrity, it does not provide a comprehensive backup solution that meets all the specified requirements.
CompTIA Security+ Study Guide
NIST SP 800-209, 'Security Guidelines for Storage Infrastructure'
'Immutable Backup Architecture' by Veeam
Which of the following are risks associated with vendor lock-in? (Select two).
Option B:Vendors changing offerings (e.g., features, pricing) can disrupt the client, a key lock-in risk.
Option D:Decreased quality of service may result from reliance on a single vendor without alternatives.
Option A:Seamless data movement is a benefit, not a risk.
Option C:Sufficient service is neutral or positive, not a risk.
Option E:Multicloud is hindered by lock-in, not a risk of it.
Option F:Increased interoperability contradicts lock-in's limitations.
Emails that the marketing department is sending to customers are going to the customers' spam folders. The security team is investigating the issue and discovers that the certificates used by the email server were reissued, but DNS records had not been updated. Which of the following should the security team update in order to fix this issue? (Select three).
The material finding from a recent compliance audit indicate a company has an issue with excessive permissions. The findings show that employees changing roles or departments results in privilege creep. Which of the following solutions are the best ways to mitigate this issue? (Select two).
Setting different access controls defined by business area
To mitigate the issue of excessive permissions and privilege creep, the best solutions are:
Implementing a Role-Based Access Policy:
Role-Based Access Control (RBAC): This policy ensures that access permissions are granted based on the user's role within the organization, aligning with the principle of least privilege. Users are only granted access necessary for their role, reducing the risk of excessive permissions.
CompTIA Security+ SY0-601 Study Guide by Mike Chapple and David Seidl
NIST Special Publication 800-53: Security and Privacy Controls for Information Systems and Organizations
Performing Periodic Access Reviews:
RegularAudits: Periodic access reviews help identify and rectify instances of privilege creep by ensuring that users' access permissions are appropriate for their current roles. These reviews can highlight unnecessary or outdated permissions, allowing for timely adjustments.
CompTIA Security+ SY0-601 Study Guide by Mike Chapple and David Seidl
ISO/IEC 27001:2013 - Information Security Management
A security architect is mitigating a vulnerability that previously led to a web application data breach. An analysis into the root cause of the issue finds the following:
An administrator's account was hijacked and used on several Autonomous System Numbers within 30 minutes.
All administrators use named accounts that require multifactor authentication.
Single sign-on is used for all company applications.Which of the following should the security architect do to mitigate the issue?
The hijacked administrator account was used across multiple ASNs (indicating different network locations) in a short time, despite MFA and SSO. This suggests a stolen session or token misuse. Let's analyze:
A . Token theft detection with lockouts:Useful for detecting stolen SSO tokens, but it's reactive and may not prevent initial misuse across networks.
B . Context-based authentication:This adds real-time checks (e.g., geolocation, IP changes) to verify login attempts. Given the rapid ASN changes, this proactively mitigates the issue by challenging suspicious logins, aligning with CAS-005's focus on adaptive security.
C . Decentralize accounts:This removes SSO, increasing complexity and weakening MFA enforcement, which isn't practical or secure.
Anthony Phillips
7 days agoGary King
18 days agoJason Roberts
30 days agoMichael Martinez
1 month agoThomas Morgan
2 months agoAngela Turner
1 month agoJustin Flores
1 month agoPaul Evans
1 month agoRachel Nguyen
2 months agoDorothy Turner
2 months agoPauline
2 months agoMarsha
3 months agoBelen
3 months agoLashaunda
3 months agoOlga
3 months agoMichal
4 months agoPok
4 months agoVanda
4 months agoShawnta
5 months agoLeatha
5 months agoAn
5 months agoDesirae
5 months agoGayla
6 months agoCecil
6 months agoLino
6 months agoHildred
6 months agoArthur
7 months agoJose
7 months agoIzetta
7 months agoCassie
7 months agoSol
8 months agoBeatriz
8 months agoLeigha
8 months agoLarae
8 months agoJesus
9 months agoTu
9 months agoGilma
9 months agoPhillip
9 months agoRolf
9 months agoMargart
12 months agoStanford
1 year agoRessie
1 year agoMillie
1 year agoLouis
1 year agoJacqueline
1 year agoMaryann
1 year agoNobuko
1 year agoOzell
1 year agoSanda
2 years agoViola
2 years agoPortia
2 years agoKristel
2 years agoBrandon
2 years agoLouvenia
2 years ago