CAS-004 Exam Question 26

A host on a company's network has been infected by a worm that appears to be spreading via SMB. A security analyst has been tasked with containing the incident while also maintaining evidence for a subsequent investigation and malware analysis.
Which of the following steps would be best to perform FIRST?
  • CAS-004 Exam Question 27

    An organization is implementing a new identity and access management architecture with the following objectives:
    Supporting MFA against on-premises infrastructure
    Improving the user experience by integrating with SaaS applications
    Applying risk-based policies based on location
    Performing just-in-time provisioning
    Which of the following authentication protocols should the organization implement to support these requirements?
  • CAS-004 Exam Question 28

    A penetration tester obtained root access on a Windows server and, according to the rules of engagement, is permitted to perform post-exploitation for persistence.
    Which of the following techniques would BEST support this?
  • CAS-004 Exam Question 29

    A small company recently developed prototype technology for a military program. The company's security engineer is concerned about potential theft of the newly developed, proprietary information.
    Which of the following should the security engineer do to BEST manage the threats proactively?
  • CAS-004 Exam Question 30

    The Chief information Officer (CIO) asks the system administrator to improve email security at the company based on the following requirements:
    * Transaction being requested by unauthorized individuals.
    * Complete discretion regarding client names, account numbers, and investment information.
    * Malicious attackers using email to malware and ransomeware.
    * Exfiltration of sensitive company information.
    The cloud-based email solution will provide anti-malware reputation-based scanning, signature-based scanning, and sandboxing. Which of the following is the BEST option to resolve the boar's concerns for this email migration?