CAS-004 Exam Question 41

An analyst execute a vulnerability scan against an internet-facing DNS server and receives the following report:

Which of the following tools should the analyst use FIRST to validate the most critical vulnerability?
  • CAS-004 Exam Question 42

    A security engineer is hardening a company's multihomed SFTP server. When scanning a public-facing network interface, the engineer finds the following ports are open:
    22
    25
    110
    137
    138
    139
    445
    Internal Windows clients are used to transferring files to the server to stage them for customer download as part of the company's distribution process.
    Which of the following would be the BEST solution to harden the system?
  • CAS-004 Exam Question 43

    The Chief information Security Officer (CISO) of a small locate bank has a compliance requirement that a third-party penetration test of the core banking application must be conducted annually. Which of the following services would fulfill the compliance requirement with the LOWEST resource usage?
  • CAS-004 Exam Question 44

    Company A acquired Company B. During an audit, a security engineer found Company B's environment was inadequately patched. In response, Company A placed a firewall between the two environments until Company B's infrastructure could be integrated into Company A's security program.
    Which of the following risk-handling techniques was used?
  • CAS-004 Exam Question 45

    A company processes data subject to NDAs with partners that define the processing and storage constraints for the covered dat a. The agreements currently do not permit moving the covered data to the cloud, and the company would like to renegotiate the terms of the agreements.
    Which of the following would MOST likely help the company gain consensus to move the data to the cloud?