CAS-005 Exam Question 36

A company's internal network is experiencing a security breach, and the threat actor is still active. Due to business requirements, users in this environment are allowed to utilize multiple machines at the same time. Given the following log snippet:

Which of the following accounts should a security analyst disable to best contain the incident without impacting valid users?
  • CAS-005 Exam Question 37

    During a recentsecurity event, access from thenon-production environment to the production environmentenabledunauthorized usersto:
    Installunapproved software
    Makeunplanned configuration changes
    During theinvestigation, the following findings were identified:
    Several new users were added in bulkby theIAM team
    Additionalfirewalls and routerswere recently added
    Vulnerability assessmentshave been disabled formore than 30 days
    Theapplication allow listhas not been modified intwo weeks
    Logs were unavailablefor various types of traffic
    Endpoints have not been patchedinover ten days
    Which of the following actions would most likely need to be taken toensure proper monitoring?(Select two)
  • CAS-005 Exam Question 38

    A security officer received several complaints from users about excessive MPA push notifications at night The security team investigates and suspects malicious activities regarding user account authentication Which of the following is the best way for the security officer to restrict MI~A notifications''
  • CAS-005 Exam Question 39

    A security engineer performed a code scan that resulted in many false positives. The security engineer must find a solution that improves the quality of scanning results before application deployment. Which of the following is the best solution?
  • CAS-005 Exam Question 40

    A company plans to implement a research facility with Intellectual property data that should be protected The following is the security diagram proposed by the security architect

    Which of the following security architect models is illustrated by the diagram?