CAS-005 Exam Question 126

A security analyst is reviewing suspicious log-in activity and sees the following data in the SICM:

Which of the following is the most appropriate action for the analyst to take?
  • CAS-005 Exam Question 127

    A security engineer is given the following requirements:
    - An endpoint must only execute Internally signed applications
    - Administrator accounts cannot install unauthorized software.
    - Attempts to run unauthorized software must be logged
    Which of the following best meets these requirements?
  • CAS-005 Exam Question 128

    A hospital provides tablets to its medical staff to enable them to more quickly access and edit patients' charts.
    The hospital wants to ensure that if a tablet is Identified as lost or stolen and a remote command is issued, the risk of data loss can be mitigated within seconds. The tablets are configured as follows to meet hospital policy
    * Full disk encryption is enabled
    * "Always On" corporate VPN is enabled
    * ef-use-backed keystore is enabled'ready.
    * Wi-Fi 6 is configured with SAE.
    * Location services is disabled.
    *Application allow list is configured
  • CAS-005 Exam Question 129

    A software engineer is creating a CI/CD pipeline to support the development of a web application The DevSecOps team is required to identify syntax errors Which of the following is the most relevant to the DevSecOps team's task'
  • CAS-005 Exam Question 130

    During a recent audit, a company's systems were assessed. Given the following information:

    Which of the following is the best way to reduce the attack surface?