CAS-004 Exam Question 71

A security analyst wants to keep track of alt outbound web connections from workstations. The analyst's company uses an on-premises web filtering solution that forwards the outbound traffic to a perimeter firewall. When the security analyst gets the connection events from the firewall, the source IP of the outbound web traffic is the translated IP of the web filtering solution. Considering this scenario involving source NAT. which of the following would be the BEST option to inject in the HTTP header to include the real source IP from workstations?
  • CAS-004 Exam Question 72

    A SOC analyst is reviewing malicious activity on an external, exposed web server. During the investigation, the analyst determines specific traffic is not being logged, and there is no visibility from the WAF for the web application.
    Which of the following is the MOST likely cause?
  • CAS-004 Exam Question 73

    A company plans to build an entirely remote workforce that utilizes a cloud-based infrastructure. The Chief Information Security Officer asks the security engineer to design connectivity to meet the following requirements:
    Only users with corporate-owned devices can directly access servers hosted by the cloud provider.
    The company can control what SaaS applications each individual user can access.
    User browser activity can be monitored.
    Which of the following solutions would BEST meet these requirements?
  • CAS-004 Exam Question 74

    An organization is planning for disaster recovery and continuity of operations.
    INSTRUCTIONS
    Review the following scenarios and instructions. Match each relevant finding to the affected host.
    After associating scenario 3 with the appropriate host(s), click the host to select the appropriate corrective action for that finding.
    Each finding may be used more than once.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    CAS-004 Exam Question 75

    A local government that is investigating a data exfiltration claim was asked to review the fingerprint of the malicious user's actions. An investigator took a forensic image of the VM an downloaded the image to a secured USB drive to share with the government. Which of the following should be taken into consideration during the process of releasing the drive to the government?