CAS-004 Exam Question 1

A company suspects a web server may have been infiltrated by a rival corporation. The security engineer reviews the web server logs and finds the following:

The security engineer looks at the code with a developer, and they determine the log entry is created when the following line is run:

Which of the following is an appropriate security control the company should implement?
  • CAS-004 Exam Question 2

    A company processes data subject to NDAs with partners that define the processing and storage constraints for the covered dat a. The agreements currently do not permit moving the covered data to the cloud, and the company would like to renegotiate the terms of the agreements.
    Which of the following would MOST likely help the company gain consensus to move the data to the cloud?
  • CAS-004 Exam Question 3

    A company requires a task to be carried by more than one person concurrently. This is an example of:
  • CAS-004 Exam Question 4

    An organization recently started processing, transmitting, and storing its customers' credit card information. Within a week of doing so, the organization suffered a massive breach that resulted in the exposure of the customers' information.
    Which of the following provides the BEST guidance for protecting such information while it is at rest and in transit?
  • CAS-004 Exam Question 5

    A security engineer needs to implement a solution to increase the security posture of user endpoints by providing more visibility and control over local administrator accounts. The endpoint security team is overwhelmed with alerts and wants a solution that has minimal operational burdens. Additionally, the solution must maintain a positive user experience after implementation.
    Which of the following is the BEST solution to meet these objectives?