CAS-004 Exam Question 6

A security analyst observes the following while looking through network traffic in a company's cloud log:

Which of the following steps should the security analyst take FIRST?
  • CAS-004 Exam Question 7

    A cloud security engineer is setting up a cloud-hosted WAF. The engineer needs to implement a solution to protect the multiple websites the organization hosts. The organization websites are:
    * www.mycompany.org
    * www.mycompany.com
    * campus.mycompany.com
    * wiki. mycompany.org
    The solution must save costs and be able to protect all websites. Users should be able to notify the cloud security engineer of any on-path attacks. Which of the following is the BEST solution?
  • CAS-004 Exam Question 8

    An organization is designing a network architecture that must meet the following requirements:
    Users will only be able to access predefined services.
    Each user will have a unique allow list defined for access.
    The system will construct one-to-one subject/object access paths dynamically.
    Which of the following architectural designs should the organization use to meet these requirements?
  • CAS-004 Exam Question 9

    The analyst should implement every solution one at a time in a virtual lab, running an attack simulation each time while collecting metrics. Roll back each solution and then implement the next. Choose the best solution based on the best metrics. This approach would allow the analyst to test each solution individually and measure its effectiveness against the attack, without affecting the other solutions or the production environment. This would also minimize the downtime required to implement the best solution, as only one change would be needed. The other options would either involve implementing multiple solutions at once, which could cause conflicts or errors, or collecting metrics before running the attack simulation, which would not reflect the actual impact of the solutions.
    Which of the following processes involves searching and collecting evidence during an investigation or lawsuit?
  • CAS-004 Exam Question 10

    A software development company makes Its software version available to customers from a web portal. On several occasions, hackers were able to access the software repository to change the package that is automatically published on the website. Which of the following would be the BEST technique to ensure the software the users download is the official software released by the company?