CAS-004 Exam Question 96

An investigator is attempting to determine if recent data breaches may be due to issues with a company's web server that offers news subscription services. The investigator has gathered the following data:
* Clients successfully establish TLS connections to web services provided by the server.
* After establishing the connections, most client connections are renegotiated
* The renegotiated sessions use cipher suite SHR.
Which of the following is the MOST likely root cause?
  • CAS-004 Exam Question 97

    A client is adding scope to a project. Which of the following processes should be used when requesting updates or corrections to the client's systems?
  • CAS-004 Exam Question 98

    A security analyst detected a malicious PowerShell attack on a single server. The malware used the Invoke-Expression function to execute an external malicious script. The security analyst scanned the disk with an antivirus application and did not find any IOCs. The security analyst now needs to deploy a protection solution against this type of malware.
    Which of the following BEST describes the type of malware the solution should protect against?
  • CAS-004 Exam Question 99

    Which of the following is used to assess compliance with internal and external requirements?
  • CAS-004 Exam Question 100

    An organization is designing a network architecture that must meet the following requirements:
    Users will only be able to access predefined services.
    Each user will have a unique allow list defined for access.
    The system will construct one-to-one subject/object access paths dynamically.
    Which of the following architectural designs should the organization use to meet these requirements?