CAS-004 Exam Question 231

A security engineer has been informed by the firewall team that a specific Windows workstation is part of a command-and-control network. The only information the security engineer is receiving is that the traffic is occurring on a non-standard port (TCP 40322). Which of the following commands should the security engineer use FIRST to find the malicious process?
  • CAS-004 Exam Question 232

    A security analyst is investigating a possible buffer overflow attack. The following output was found on a user's workstation:
    graphic.linux_randomization.prg
    Which of the following technologies would mitigate the manipulation of memory segments?
  • CAS-004 Exam Question 233

    An organization developed a social media application that is used by customers in multiple remote geographic locations around the world. The organization's headquarters and only datacenter are located in New York City.
    The Chief Information Security Officer wants to ensure the following requirements are met for the social media application:
    Low latency for all mobile users to improve the users' experience
    SSL offloading to improve web server performance
    Protection against DoS and DDoS attacks
    High availability
    Which of the following should the organization implement to BEST ensure all requirements are met?
  • CAS-004 Exam Question 234

    A system administrator at a medical imaging company discovers protected health information (PHI) on a general-purpose file server. Which of the following steps should the administrator take NEXT?
  • CAS-004 Exam Question 235

    A cybersecurity engineer analyst a system for vulnerabilities. The tool created an OVAL. Results document as output. Which of the following would enable the engineer to interpret the results in a human readable form?
    (Select TWO.)