CAS-004 Exam Question 111

A cybersecurity analyst receives a ticket that indicates a potential incident is occurring. There has been a large in log files generated by a generated by a website containing a ''Contact US'' form. The analyst must determine if the increase in website traffic is due to a recent marketing campaign of if this is a potential incident. Which of the following would BEST assist the analyst?
  • CAS-004 Exam Question 112

    A bank hired a security architect to improve its security measures against the latest threats The solution must meet the following requirements
    * Recognize and block fake websites
    * Decrypt and scan encrypted traffic on standard and non-standard ports
    * Use multiple engines for detection and prevention
    * Have central reporting
    Which of the following is the BEST solution the security architect can propose?
  • CAS-004 Exam Question 113

    A security operations center analyst is investigating anomalous activity between a database server and an unknown external IP address and gathered the following data:
    * dbadmin last logged in at 7:30 a.m. and logged out at 8:05 a.m.
    * A persistent TCP/6667 connection to the external address was established at 7:55 a.m. The connection is still active.
    * Other than bytes transferred to keep the connection alive, only a few kilobytes of data transfer every hour since the start of the connection.
    * A sample outbound request payload from PCAP showed the ASCII content: "JOIN #community".
    Which of the following is the MOST likely root cause?
  • CAS-004 Exam Question 114

    A security architect is designing a solution for a new customer who requires significant security capabilities in its environment. The customer has provided the architect with the following set of requirements:
    * Capable of early detection of advanced persistent threats.
    * Must be transparent to users and cause no performance degradation.
    + Allow integration with production and development networks seamlessly.
    + Enable the security team to hunt and investigate live exploitation techniques.
    Which of the following technologies BEST meets the customer's requirements for security capabilities?
  • CAS-004 Exam Question 115

    A security analyst runs a vulnerability scan on a network administrator's workstation.
    The network administrator has direct administrative access to the company's SSO web portal.
    The vulnerability scan uncovers cntical vulnerabilities with equally high CVSS scores for the user's browser, OS, email client and an offline password manager.
    Which of the following should the security analyst patch FIRST?