CAS-004 Exam Question 246

A small company recently developed prototype technology for a military program. The company's security engineer is concerned about potential theft of the newly developed, proprietary information.
Which of the following should the security engineer do to BEST manage the threats proactively?
  • CAS-004 Exam Question 247

    A security analyst is reading the results of a successful exploit that was recently conducted by third-party penetration testers. The testers reverse engineered a privileged executable. In the report, the planning and execution of the exploit is detailed using logs and outputs from the test However, the attack vector of the exploit is missing, making it harder to recommend remediation's. Given the following output:

    The penetration testers MOST likely took advantage of:
  • CAS-004 Exam Question 248

    Users are reporting intermittent access issues with & new cloud application that was recently added to the network. Upon investigation, he scary administrator notices the human resources department Is able to run required queries with the new application, but the marketing department is unable to pull any needed reports on various resources using the new application. Which of the following MOST likely needs to be done to avoid this in the future?
  • CAS-004 Exam Question 249

    An organization is deploying a new, online digital bank and needs to ensure availability and performance. The cloud-based architecture is deployed using PaaS and SaaS solutions, and it was designed with the following considerations:
    - Protection from DoS attacks against its infrastructure and web applications is in place.
    - Highly available and distributed DNS is implemented.
    - Static content is cached in the CDN.
    - A WAF is deployed inline and is in block mode.
    - Multiple public clouds are utilized in an active-passive architecture.
    With the above controls in place, the bank is experiencing a slowdown on the unauthenticated payments page.
    Which of the following is the MOST likely cause?
  • CAS-004 Exam Question 250

    A company is implementing SSL inspection. During the next six months, multiple web applications that will be separated out with subdomains will be deployed.
    Which of the following will allow the inspection of the data without multiple certificate deployments?