CAS-004 Exam Question 16

A company is moving most of its customer-facing production systems to the cloud-facing production systems to the cloud. IaaS is the service model being used. The Chief Executive Officer is concerned about the type of encryption available and requires the solution must have the highest level of security.
Which of the following encryption methods should the cloud security engineer select during the implementation phase?
  • CAS-004 Exam Question 17

    An organization decided to begin issuing corporate mobile device users microSD HSMs that must be installed in the mobile devices in order to access corporate resources remotely Which of the following features of these devices MOST likely led to this decision? (Select TWO.)
  • CAS-004 Exam Question 18

    A high-severity vulnerability was found on a web application and introduced to the enterprise. The vulnerability could allow an unauthorized user to utilize an open-source library to view privileged user information. The enterprise is unwilling to accept the risk, but the developers cannot fix the issue right away.
    Which of the following should be implemented to reduce the risk to an acceptable level until the issue can be fixed?
  • CAS-004 Exam Question 19

    A company hired a third party to develop software as part of its strategy to be quicker to market. The company's policy outlines the following requirements:
    The credentials used to publish production software to the container registry should be stored in a secure location.
    Access should be restricted to the pipeline service account, without the ability for the third-party developer to read the credentials directly.
    Which of the following would be the BEST recommendation for storing and monitoring access to these shared credentials?
  • CAS-004 Exam Question 20

    A security engineer needs to recommend a solution that will meet the following requirements:
    Identify sensitive data in the provider's network
    Maintain compliance with company and regulatory guidelines
    Detect and respond to insider threats, privileged user threats, and compromised accounts Enforce datacentric security, such as encryption, tokenization, and access control Which of the following solutions should the security engineer recommend to address these requirements?