CAS-004 Exam Question 31

Which of the following allows computation and analysis of data within a ciphertext without knowledge of the plaintext?
  • CAS-004 Exam Question 32

    A company wants to protect its intellectual property from theft. The company has already applied ACLs and DACs.
    Which of the following should the company use to prevent data theft?
  • CAS-004 Exam Question 33

    An organization's existing infrastructure includes site-to-site VPNs between datacenters. In the past year, a sophisticated attacker exploited a zero-day vulnerability on the VPN concentrator. Consequently, the Chief Information Security Officer (CISO) is making infrastructure changes to mitigate the risk of service loss should another zero-day exploit be used against the VPN solution.
    Which of the following designs would be BEST for the CISO to use?
  • CAS-004 Exam Question 34

    A security auditor needs to review the manner in which an entertainment device operates. The auditor is analyzing the output of a port scanning tool to determine the next steps in the security review. Given the following log output.
    The best option for the auditor to use NEXT is:
  • CAS-004 Exam Question 35

    An organization is referencing NIST best practices for BCP creation while reviewing current internal organizational processes for mission-essential items.
    Which of the following phases establishes the identification and prioritization of critical systems and functions?