CAS-004 Exam Question 201
A company undergoing digital transformation is reviewing the resiliency of a CSP and is concerned about meeting SLA requirements in the event of a CSP incident.
Which of the following would be BEST to proceed with the transformation?
Which of the following would be BEST to proceed with the transformation?
CAS-004 Exam Question 202
An organization recently recovered from an attack that featured an adversary injecting malicious logic into OS bootloaders on endpoint devices. Therefore, the organization decided to require the use of TPM for measured boot and attestation, monitoring each component from the UEFI through the full loading of OS components. Which of the following TPM structures enables this storage functionality?
CAS-004 Exam Question 203
An employee decides to log into an authorized system.
The system does not prompt the employee for authentication prior to granting access to the console, and it cannot authenticate the network resources.
Which of the following attack types can this lead to if it is not mitigated?
The system does not prompt the employee for authentication prior to granting access to the console, and it cannot authenticate the network resources.
Which of the following attack types can this lead to if it is not mitigated?
CAS-004 Exam Question 204
A threat analyst notices the following URL while going through the HTTP logs.

Which of the following attack types is the threat analyst seeing?

Which of the following attack types is the threat analyst seeing?
CAS-004 Exam Question 205
A company security engineer arrives at work to face the following scenario:
1) Website defacement
2) Calls from the company president indicating the website needs to be fixed Immediately because It Is damaging the brand
3) A Job offer from the company's competitor
4) A security analyst's investigative report, based on logs from the past six months, describing how lateral movement across the network from various IP addresses originating from a foreign adversary country resulted in exfiltrated data Which of the following threat actors Is MOST likely involved?
1) Website defacement
2) Calls from the company president indicating the website needs to be fixed Immediately because It Is damaging the brand
3) A Job offer from the company's competitor
4) A security analyst's investigative report, based on logs from the past six months, describing how lateral movement across the network from various IP addresses originating from a foreign adversary country resulted in exfiltrated data Which of the following threat actors Is MOST likely involved?
