CAS-005 Exam Question 86

A company must build and deploy security standards for all servers in its on-premises and cloud environments based on hardening guidelines. Which of the following solutions most likely meets the requirements?
  • CAS-005 Exam Question 87

    A security analyst Detected unusual network traffic related to program updating processes The analyst collected artifacts from compromised user workstations. The discovered artifacts were binary files with the same name as existing, valid binaries but. with different hashes which of the following solutions would most likely prevent this situation from reoccurring?
  • CAS-005 Exam Question 88

    A security professional is investigating a trend in vulnerability findings for newly deployed cloud systems Given the following output:

    Which of the following actions would address the root cause of this issue?
  • CAS-005 Exam Question 89

    SIMULATION
    [Identity and Access Management (IAM)]
    A product development team has submitted code snippets for review prior to release.
    INSTRUCTIONS
    Analyze the code snippets, and then select one vulnerability, and one fix for each code snippet.
    Code Snippet 1

    Code Snippet 2

    Vulnerability 1:
    SQL injection
    Cross-site request forgery
    Server-side request forgery
    Indirect object reference
    Cross-site scripting
    Fix 1:
    Perform input sanitization of the userid field.
    Perform output encoding of queryResponse,
    Ensure usex:ia belongs to logged-in user.
    Inspect URLS and disallow arbitrary requests.
    Implementanti-forgery tokens.
    Vulnerability 2
    1) Denial of service
    2) Command injection
    3) SQL injection
    4) Authorization bypass
    5) Credentials passed via GET
    Fix 2
    A) Implement prepared statements and bind
    variables.
    B) Remove the serve_forever instruction.
    C) Prevent the "authenticated" value from being overridden by a GET parameter.
    D) HTTP POST should be used for sensitive parameters.
    E) Perform input sanitization of the userid field.

    CAS-005 Exam Question 90

    A security analyst notices a number of SIEM events that show the following activity:
    10/30/2020 - 8:01 UTC - 192.168.1.1 - sc stop HinDctend
    10/30/2020 - 8:05 UTC - 192.168.1.2 - c:\program files\games\comptidcasp.exe
    10/30/2020 - 8:07 UTC - 192.168.1.1 - c:\windows\system32\cmd.exe /c powershell
    10/30/2020 - 8:07 UTC - 192.168.1.1 - powershell -> 40.90.23.154:443
    Which of the following response actions should the analyst take first?