CAS-004 Exam Question 51

Ransomware encrypted the entire human resources fileshare for a large financial institution. Security operations personnel were unaware of the activity until it was too late to stop it. The restoration will take approximately four hours, and the last backup occurred 48 hours ago. The management team has indicated that the RPO for a disaster recovery event for this data classification is 24 hours.
Based on RPO requirements, which of the following recommendations should the management team make?
  • CAS-004 Exam Question 52

    A small business requires a low-cost approach to theft detection for the audio recordings it produces and sells.
    Which of the following techniques will MOST likely meet the business's needs?
  • CAS-004 Exam Question 53

    A security engineer estimates the company's popular web application experiences 100 attempted breaches per day. In the past four years, the company's data has been breached two times.
    Which of the following should the engineer report as the ARO for successful breaches?
  • CAS-004 Exam Question 54

    A large number of emails have been reported, and a security analyst is reviewing the following information from the emails:

    As part of the image process, which of the following is the FIRST step the analyst should take?
  • CAS-004 Exam Question 55

    A security analyst receives an alert from the SIEM regarding unusual activity on an authorized public SSH jump server. To further investigate, the analyst pulls the event logs directly from /var/log/auth.log: graphic.ssh_auth_log.
    Which of the following actions would BEST address the potential risks by the activity in the logs?