Exam CISA All QuestionsBrowse all questions from this exam
Question 1043

A web proxy server for corporate connections to external resources reduces organizational risk by:

    Correct Answer: C

    A web proxy server reduces organizational risk by anonymizing users through changed IP addresses. When employees access external resources through the proxy server, their actual IP addresses are hidden, and only the IP address of the proxy server is visible. This adds a layer of security and privacy, making it harder for external entities to track or target individual users within the organization, thus protecting against cyber threats such as reconnaissance attacks and data leakage.

Discussion
SuperMaxOption: C

C. anonymizing users through changed IP addresses. A web proxy server can help reduce organizational risk by anonymizing users through changed IP addresses. This means that when employees access external resources through the proxy server, their actual IP addresses are hidden, and only the IP address of the proxy server is visible to external websites and services. This can provide an additional layer of security and privacy, making it more difficult for external entities to track or target individual users within the organization. This can help protect against various forms of cyber threats, including reconnaissance attacks and data leakage. While the other options mentioned (load balancing, multi-factor authentication, and faster response) can be benefits of using a web proxy server, they do not directly address the aspect of risk reduction associated with user anonymity.

FAGFUROption: B

A web proxy server for corporate connections to external resources reduces organizational risk by providing multi-factor authentication for additional security. Multi-factor authentication adds an extra layer of protection beyond just usernames and passwords, making it more difficult for unauthorized users to gain access to corporate resources. This is especially important when users are accessing external resources over the internet.

SwallowsOption: B

Option C, "Anonymizing users by changing their IP addresses," may be a valid approach in some scenarios, but its risk mitigation is limited. Changing the IP address may improve anonymity, but it alone cannot completely mitigate the risk. Robust authentication is important, especially when accessing external resources. Therefore, the most effective way to mitigate risk when connecting to a company's external resources is to provide multi-factor authentication as an additional security measure.