CAS-004 Exam Question 46
An enterprise is deploying APIs that utilize a private key and a public key to ensure the connection string is protected. To connect to the API, customers must use the private key.
Which of the following would BEST secure the REST API connection to the database while preventing the use of a hard-coded string in the request string?
Which of the following would BEST secure the REST API connection to the database while preventing the use of a hard-coded string in the request string?
CAS-004 Exam Question 47
A security analyst is reviewing the following vulnerability assessment report:

Which of the following should be patched FIRST to minimize attacks against Internet-facing hosts?

Which of the following should be patched FIRST to minimize attacks against Internet-facing hosts?
CAS-004 Exam Question 48
An administrator at a software development company would like to protect the integrity of the company's applications with digital signatures. The developers report that the signing process keeps failing on all applications. The same key pair used for signing, however, is working properly on the website, is valid, and is issued by a trusted CA. Which of the following is MOST likely the cause of the signature failing?
CAS-004 Exam Question 49
A company that uses AD is migrating services from LDAP to secure LDAP. During the pilot phase, services are not connecting properly to secure LDAP. Block is an except of output from the troubleshooting session:

Which of the following BEST explains why secure LDAP is not working? (Select TWO.)

Which of the following BEST explains why secure LDAP is not working? (Select TWO.)
CAS-004 Exam Question 50
A consultant is planning an assessment of a customer-developed system.
The system consists of a custom-engineered board with modified open-source drivers and a one- off management GUI.
The system relies on two- factor authentication for interactive sessions, employs strong certificate-based data-in-transit encryption, and randomly switches ports for each session.
Which of the following would yield the MOST useful information'?
The system consists of a custom-engineered board with modified open-source drivers and a one- off management GUI.
The system relies on two- factor authentication for interactive sessions, employs strong certificate-based data-in-transit encryption, and randomly switches ports for each session.
Which of the following would yield the MOST useful information'?
