CAS-004 Exam Question 21

A security architect is reviewing the following proposed corporate firewall architecture and configuration:

Both firewalls are stateful and provide Layer 7 filtering and routing. The company has the following requirements:
Web servers must receive all updates via HTTP/S from the corporate network.
Web servers should not initiate communication with the Internet.
Web servers should only connect to preapproved corporate database servers.
Employees' computing devices should only connect to web services over ports 80 and 443.
Which of the following should the architect recommend to ensure all requirements are met in the MOST secure manner? (Choose two.)
  • CAS-004 Exam Question 22

    A financial services company wants to migrate its email services from on-premises servers to a cloud-based email solution. The Chief information Security Officer (CISO) must brief board of directors on the potential security concerns related to this migration. The board is concerned about the following.
    * Transactions being required by unauthorized individual
    * Complete discretion regarding client names, account numbers, and investment information.
    * Malicious attacker using email to distribute malware and ransom ware.
    * Exfiltration of sensitivity company information.
    The cloud-based email solution will provide an6-malware, reputation-based scanning, signature-based scanning, and sandboxing. Which of the following is the BEST option to resolve the board's concerns for this email migration?
  • CAS-004 Exam Question 23

    A company based in the United States holds insurance details of EU citizens. Which of the following must be adhered to when processing EU citizens' personal, private, and confidential data?
  • CAS-004 Exam Question 24

    A penetration tester obtained root access on a Windows server and, according to the rules of engagement, is permitted to perform post-exploitation for persistence.
    Which of the following techniques would BEST support this?
  • CAS-004 Exam Question 25

    The goal of a Chief information Security Officer (CISO) providing up-to-date metrics to a bank's risk committee is to ensure: