CAS-004 Exam Question 211


An organization is planning for disaster recovery and continuity of operations.
INSTRUCTIONS
Review the following scenarios and instructions. Match each relevant finding to the affected host.
After associating scenario 3 with the appropriate host(s), click the host to select the appropriate corrective action for that finding.
Each finding may be used more than once.If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

CAS-004 Exam Question 212

A financial institution has several that currently employ the following controls:
- The severs follow a monthly patching cycle.
- All changes must go through a change management process.
- Developers and systems administrators must log into a jumpbox to
access the servers hosting the data using two-factor authentication.
- The servers are on an isolated VLAN and cannot be directly accessed
from the internal production network.
An outage recently occurred and lasted several days due to an upgrade that circumvented the approval process. Once the security team discovered an unauthorized patch was installed, they were able to resume operations within an hour. Which of the following should the security administrator recommend to reduce the time to resolution if a similar incident occurs in the future?
  • CAS-004 Exam Question 213

    Which of the following describes the system responsible for storing private encryption/decryption files with a third party to ensure these files are stored safely?
  • CAS-004 Exam Question 214

    A company's claims processed department has a mobile workforce that receives a large number of email submissions from personal email addresses. An employees recently received an email that approved to be claim form, but it installed malicious software on the employee's laptop when was opened.
  • CAS-004 Exam Question 215

    In order to authenticate employees who, call in remotely, a company's help desk staff must be able to view partial Information about employees because the full information may be considered sensitive. Which of the following solutions should be implemented to authenticate employees?