CAS-004 Exam Question 66

A company wants to quantify and communicate the effectiveness of its security controls but must establish measures. Which of the following is MOST likely to be included in an effective assessment roadmap for these controls?
  • CAS-004 Exam Question 67

    A company launched a new service and created a landing page within its website network for users to access the service. Per company policy, all websites must utilize encryption for any authentication pages. A junior network administrator proceeded to use an outdated procedure to order new certificates. Afterward, customers are reporting the following error when accessing a new web page: NET:ERR_CERT_COMMON_NAME_INVALID. Which of the following BEST describes what the administrator should do NEXT?
  • CAS-004 Exam Question 68

    A network architect is designing a new SD-WAN architecture to connect all local sites to a central hub site. The hub is then responsible for redirecting traffic to public cloud and datacenter applications. The SD-WAN routers are managed through a SaaS, and the same security policy is applied to staff whether working in the office or at a remote location. The main requirements are the following:
    1. The network supports core applications that have 99.99% uptime.
    2. Configuration updates to the SD-WAN routers can only be initiated from the management service.
    3. Documents downloaded from websites must be scanned for malware.
    Which of the following solutions should the network architect implement to meet the requirements?
  • CAS-004 Exam Question 69

    An attack team performed a penetration test on a new smart card system. The team demonstrated that by subjecting the smart card to high temperatures, the secret key could be revealed.
    Which of the following side-channel attacks did the team use?
  • CAS-004 Exam Question 70

    An organization is researching the automation capabilities for systems within an OT network. A security analyst wants to assist with creating secure coding practices and would like to learn about the programming languages used on the PLCs. Which of the following programming languages is the MOST relevant for PLCs?