CAS-004 Exam Question 36

An auditor Is reviewing the logs from a web application to determine the source of an Incident. The web application architecture Includes an Internet-accessible application load balancer, a number of web servers In a private subnet, application servers, and one database server In a tiered configuration. The application load balancer cannot store the logs. The following are sample log snippets:

Which of the following should the auditor recommend to ensure future incidents can be traced back to the sources?
  • CAS-004 Exam Question 37

    A large number of emails have been reported, and a security analyst is reviewing the following information from the emails:

    As part of the image process, which of the following is the FIRST step the analyst should take?
  • CAS-004 Exam Question 38

    A Chief Information Security Officer (CISO) is concerned that a company's current data disposal procedures could result in data remanence. The company uses only SSDs. Which of the following would be the MOST secure way to dispose of the SSDs given the CISO's concern?
  • CAS-004 Exam Question 39

    A Chief Information Officer is considering migrating all company data to the cloud to save money on expensive SAN storage.
    Which of the following is a security concern that will MOST likely need to be addressed during migration?
  • CAS-004 Exam Question 40

    A company has decided that only administrators are permitted to use PowerShell on their Windows computers.
    Which of the following is the BEST way for an administrator to implement this decision?
    Monitor the Application and Services Logs group within Windows Event Log.