CAS-004 Exam Question 236

A Chief Information Officer (CIO) wants to implement a cloud solution that will satisfy the following requirements:
Support all phases of the SDLC.
Use tailored website portal software.
Allow the company to build and use its own gateway software.
Utilize its own data management platform.
Continue using agent-based security tools.
Which of the following cloud-computing models should the CIO implement?
  • CAS-004 Exam Question 237

    Designing a system in which only information that is essential for a particular job task is allowed to be viewed can be accomplished successfully by using:
  • CAS-004 Exam Question 238

    A company is outsourcing to an MSSP that performs managed detection and response services. The MSSP requires a server to be placed inside the network as a log aggregate and allows remote access to MSSP analyst.
    Critical devices send logs to the log aggregator, where data is stored for 12 months locally before being archived to a multitenant cloud. The data is then sent from the log aggregate to a public IP address in the MSSP datacenter for analysis.
    A security engineer is concerned about the security of the solution and notes the following.
    * The critical devise send cleartext logs to the aggregator.
    * The log aggregator utilize full disk encryption.
    * The log aggregator sends to the analysis server via port 80.
    * MSSP analysis utilize an SSL VPN with MFA to access the log aggregator remotely.
    * The data is compressed and encrypted prior to being achieved in the cloud.
    Which of the following should be the engineer's GREATEST concern?
  • CAS-004 Exam Question 239

    Some end users of an e-commerce website are reporting a delay when browsing pages. The website uses TLS 1.2. A security architect for the website troubleshoots by connecting from home to the website and capturing tramc via Wire-shark. The security architect finds that the issue is the time required to validate the certificate. Which of the following solutions should the security architect recommend?
  • CAS-004 Exam Question 240

    A company is deploying multiple VPNs to support supplier connections into its extranet applications. The network security standard requires:
    * All remote devices to have up-to-date antivirus
    * An up-to-date and patched OS
    Which of the following technologies should the company deploy to meet its security objectives? (Select TWO)_