CAS-004 Exam Question 6

A network administrator who manages a Linux web server notices the following traffic:
http://corr.ptia.org/.../.../.../...
/etc./shadow
Which of the following Is the BEST action for the network administrator to take to defend against this type of web attack?
  • CAS-004 Exam Question 7

    Company A acquired Company B. During an initial assessment, the companies discover they are using the same SSO system. To help users with the transition, Company A is requiring the following:
    * Before the merger is complete, users from both companies should use a single set of usernames and passwords.
    * Users in the same departments should have the same set of rights and privileges, but they should have different sets of rights and privileges if they have different IPs.
    * Users from Company B should be able to access Company A's available resources.
    Which of the following are the BEST solutions? (Select TWO).
  • CAS-004 Exam Question 8

    An auditor Is reviewing the logs from a web application to determine the source of an Incident. The web application architecture Includes an Internet-accessible application load balancer, a number of web servers In a private subnet, application servers, and one database server In a tiered configuration. The application load balancer cannot store the logs. The following are sample log snippets:

    Which of the following should the auditor recommend to ensure future incidents can be traced back to the sources?
  • CAS-004 Exam Question 9

    A software development company is building a new mobile application for its social media platform. The company wants to gain its Users' rust by reducing the risk of on-path attacks between the mobile client and its servers and by implementing stronger digital trust. To support users' trust, the company has released the following internal guidelines:
    * Mobile clients should verify the identity of all social media servers locally.
    * Social media servers should improve TLS performance of their certificate status.
    * Social media servers should inform the client to only use HTTPS.
    Given the above requirements, which of the following should the company implement? (Select TWO).
  • CAS-004 Exam Question 10

    A cybersecurity analyst discovered a private key that could have been exposed.
    Which of the following is the BEST way for the analyst to determine if the key has been compromised?