CAS-004 Exam Question 6

Company A acquired Company B. During an audit, a security engineer found Company B's environment was inadequately patched. In response, Company A placed a firewall between the two environments until Company B's infrastructure could be integrated into Company A's security program.
Which of the following risk-handling techniques was used?
  • CAS-004 Exam Question 7

    A satellite communications ISP frequently experiences outages and degraded modes of operation over one of its legacy satellite links due to the use of deprecated hardware and software. Three days per week, on average, a contracted company must follow a checklist of 16 different high-latency commands that must be run in serial to restore nominal performance. The ISP wants this process to be automated.
    Which of the following techniques would be BEST suited for this requirement?
  • CAS-004 Exam Question 8

    A new web server must comply with new secure-by-design principles and PCI DSS. This includes mitigating the risk of an on-path attack. A security analyst is reviewing the following web server configuration:

    Which of the following ciphers should the security analyst remove to support the business requirements?
  • CAS-004 Exam Question 9

    A forensic investigator would use the foremost command for:
  • CAS-004 Exam Question 10

    A home automation company just purchased and installed tools for its SOC to enable incident identification and response on software the company develops. The company would like to prioritize defenses against the following attack scenarios:
    Unauthorized insertions into application development environments
    Authorized insiders making unauthorized changes to environment configurations
    Which of the following actions will enable the data feeds needed to detect these types of attacks on development environments? (Choose two.)