CAS-004 Exam Question 41

A business stores personal client data of individuals residing in the EU in order to process requests for mortgage loan approvals.
Which of the following does the business's IT manager need to consider?
  • CAS-004 Exam Question 42

    A security analyst discovered that a database administrator's workstation was compromised by malware. After examining the Jogs. the compromised workstation was observed connecting to multiple databases through ODBC. The following query behavior was captured:

    Assuming this query was used to acquire and exfiltrate data, which of the following types of data was compromised, and what steps should the incident response plan contain?
    A) Personal health information: Inform the human resources department of the breach and review the DLP logs.
    B) Account history; Inform the relationship managers of the breach and create new accounts for the affected users.
    C) Customer IDs: Inform the customer service department of the breach and work to change the account numbers.
    D) PAN: Inform the legal department of the breach and look for this data in dark web monitoring.
  • CAS-004 Exam Question 43

    A financial institution has several that currently employ the following controls:
    * The severs follow a monthly patching cycle.
    * All changes must go through a change management process.
    * Developers and systems administrators must log into a jumpbox to access the servers hosting the data using two-factor authentication.
    * The servers are on an isolated VLAN and cannot be directly accessed from the internal production network.
    An outage recently occurred and lasted several days due to an upgrade that circumvented the approval process. Once the security team discovered an unauthorized patch was installed, they were able to resume operations within an hour. Which of the following should the security administrator recommend to reduce the time to resolution if a similar incident occurs in the future?
  • CAS-004 Exam Question 44

    A vulnerability analyst identified a zero-day vulnerability in a company's internally developed software. Since the current vulnerability management system does not have any checks for this vulnerability, an engineer has been asked to create one.
    Which of the following would be BEST suited to meet these requirements?
  • CAS-004 Exam Question 45

    A company hired a third party to develop software as part of its strategy to be quicker to market. The company's policy outlines the following requirements:
    The credentials used to publish production software to the container registry should be stored in a secure location.
    Access should be restricted to the pipeline service account, without the ability for the third-party developer to read the credentials directly.
    Which of the following would be the BEST recommendation for storing and monitoring access to these shared credentials?