CAS-004 Exam Question 216

An organization is planning for disaster recovery and continuity of operations.
INSTRUCTIONS
Review the following scenarios and instructions. Match each relevant finding to the affected host.
After associating scenario 3 with the appropriate host(s), click the host to select the appropriate corrective action for that finding.
Each finding may be used more than once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

CAS-004 Exam Question 217

A security architect is implementing a web application that uses a database back end. Prior to the production, the architect is concerned about the possibility of XSS attacks and wants to identify security controls that could be put in place to prevent these attacks.
Which of the following sources could the architect consult to address this security concern?
  • CAS-004 Exam Question 218

    An IPSec solution is being deployed. The configuration files for both the VPN concentrator and the AAA server are shown in the diagram.
    Complete the configuration files to meet the following requirements:
    * The EAP method must use mutual certificate-based authentication (With issued client certificates).
    * The IKEv2 Cipher suite must be configured to the MOST secure
    authenticated mode of operation,
    * The secret must contain at least one uppercase character, one lowercase character, one numeric character, and one special character, and it must meet a minimum length requirement of eight characters, INSTRUCTIONS Click on the AAA server and VPN concentrator to complete the configuration.
    Fill in the appropriate fields and make selections from the drop-down menus.

    VPN Concentrator:

    AAA Server:

    CAS-004 Exam Question 219

    A financial institution has several that currently employ the following controls:
    * The severs follow a monthly patching cycle.
    * All changes must go through a change management process.
    * Developers and systems administrators must log into a jumpbox to access the servers hosting the data using two-factor authentication.
    * The servers are on an isolated VLAN and cannot be directly accessed from the internal production network.
    An outage recently occurred and lasted several days due to an upgrade that circumvented the approval process.
    Once the security team discovered an unauthorized patch was installed, they were able to resume operations within an hour. Which of the following should the security administrator recommend to reduce the time to resolution if a similar incident occurs in the future?
  • CAS-004 Exam Question 220

    Which of the following may indicate a configuration item has reached end-of-life?