4.5 Given a scenario, modify enterprise capabilities to enhance security

Domain 4: Security Operations

Objective 4.5 is the hands-on configuration objective: given a security goal, modify an enterprise capability to achieve it. That spans firewall rules and screened subnets, IDS versus IPS placement and modes, web filtering (agent-based, centralized proxy, URL and reputation filtering), operating system hardening through Group Policy and SELinux, secure protocol selection including port and transport choices, DNS filtering, email security with DMARC, DKIM, and SPF, file integrity monitoring, DLP enforcement, network access control, EDR and XDR, and user behavior analytics. Questions are scenario-driven: read what the organization wants to block, detect, or allow, then pick the capability and the specific setting. Practice reading firewall rule logic, including implicit deny and rule order. Know why an IPS sits inline and an IDS does not, and what fail-open versus fail-closed implies. The classic stumble is email authentication: SPF validates sending servers, DKIM signs messages, and DMARC tells receivers what to do when either check fails — candidates who memorize the trio superficially mix up their roles under pressure.

What you must know

common pitfall · Candidates scramble the email authentication trio, forgetting that SPF authorizes sending servers, DKIM cryptographically signs mail, and DMARC sets the policy for failures.

Try a sample question

Employees keep clicking links in phishing emails that lead to newly registered domains hosting credential-harvesting pages. The secure email gateway already blocks malicious attachments effectively. Which of the following changes would BEST reduce the risk from these links?

  • A Deploy DNS filtering that blocks resolution of newly registered and uncategorized domains
  • B Expand attachment sandboxing capacity on the secure email gateway
  • C Require agent-based NAC posture checks before devices join the network
  • D Enable additional IPS signatures for known exploit traffic at the perimeter
Show answer & explanations
  • A correct ·DNS filtering can block resolution of newly registered and uncategorized domains, stopping the connection before the credential-harvesting page ever loads, which directly counters the link-clicking behavior described.
  • B Expanding attachment sandboxing strengthens a control that is already working well; these attacks succeed through clicked links rather than attachments, so the change misses the actual threat vector.
  • C NAC posture checks validate device health before granting network access; they do not evaluate or block the external destinations users browse to after their devices are connected.
  • D IPS signatures match known exploit patterns in network traffic; credential-harvesting pages rely on users voluntarily typing passwords, which produces no exploit signature for the IPS to detect.

sample item — the full bank runs 450+ questions at exam difficulty

Is objective 4.5 your weak spot?

The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.

Check my readiness — free