CAS-004 Exam Question 26

A user from the sales department opened a suspicious file attachment. The sales department then contacted the SOC to investigate a number of unresponsive systems, and the team successfully identified the file and the origin of the attack.
Which of the following is the NEXT step of the incident response plan?
  • CAS-004 Exam Question 27

    A security engineer was auditing an organization's current software development practice and discovered that multiple open-source libraries were Integrated into the organization's software. The organization currently performs SAST and DAST on the software it develops.
    Which of the following should the organization incorporate into the SDLC to ensure the security of the open-source libraries?
  • CAS-004 Exam Question 28

    A company is looking for a solution to hide data stored in databases. The solution must meet the following requirements:
    Be efficient at protecting the production environment
    Not require any change to the application
    Act at the presentation layer
    Which of the following techniques should be used?
  • CAS-004 Exam Question 29

    A development team created a mobile application that contacts a company's back-end APIs housed in a PaaS environment. The APIs have been experiencing high processor utilization due to scraping activities. The security engineer needs to recommend a solution that will prevent and remedy the behavior.
    Which of the following would BEST safeguard the APIs? (Choose two.)
  • CAS-004 Exam Question 30

    A security consultant needs to set up wireless security for a small office that does not have Active Directory. Despite the lack of central account management, the office manager wants to ensure a high level of defense to prevent brute-force attacks against wireless authentication.
    Which of the following technologies would BEST meet this need?