CAS-004 Exam Question 16

An organization is researching the automation capabilities for systems within an OT network. A security analyst wants to assist with creating secure coding practices and would like to learn about the programming languages used on the PLCs. Which of the following programming languages is the MOST relevant for PLCs?
  • CAS-004 Exam Question 17

    A Chief Information Officer (CIO) wants to implement a cloud solution that will satisfy the following requirements:
    Support all phases of the SDLC.
    Use tailored website portal software.
    Allow the company to build and use its own gateway software.
    Utilize its own data management platform.
    Continue using agent-based security tools.
    Which of the following cloud-computing models should the CIO implement?
  • CAS-004 Exam Question 18

    A company is outsourcing to an MSSP that performs managed detection and response services. The MSSP requires a server to be placed inside the network as a log aggregate and allows remote access to MSSP analyst. Critical devices send logs to the log aggregator, where data is stored for 12 months locally before being archived to a multitenant cloud. The data is then sent from the log aggregate to a public IP address in the MSSP datacenter for analysis.
    A security engineer is concerned about the security of the solution and notes the following.
    * The critical devise send cleartext logs to the aggregator.
    * The log aggregator utilize full disk encryption.
    * The log aggregator sends to the analysis server via port 80.
    * MSSP analysis utilize an SSL VPN with MFA to access the log aggregator remotely.
    * The data is compressed and encrypted prior to being achieved in the cloud.
    Which of the following should be the engineer's GREATEST concern?
  • CAS-004 Exam Question 19

    A security analyst discovered that the company's WAF was not properly configured. The main web server was breached, and the following payload was found in one of the malicious requests:

    Which of the following would BEST mitigate this vulnerability?
  • CAS-004 Exam Question 20

    A security is assisting the marketing department with ensuring the security of the organization's social media platforms. The two main concerns are:
    The Chief marketing officer (CMO) email is being used department wide as the username The password has been shared within the department Which of the following controls would be BEST for the analyst to recommend?