CAS-005 Exam Question 91

An enterprise is deploying APIs that utilize a private key and a public key to ensure the connection string is protected. To connect to the API, customers must use the private key. Which of the following would best secure the REST API connection to the database while preventing the use of a hard-coded string in the request string?
  • CAS-005 Exam Question 92

    After an incident occurred, a team reported during the lessons-learned review that the team.
    * Lost important Information for further analysis.
    * Did not utilize the chain of communication
    * Did not follow the right steps for a proper response
    Which of the following solutions is the best way to address these findinds?
  • CAS-005 Exam Question 93

    An organization is required to
    * Respond to internal and external inquiries in a timely manner
    * Provide transparency.
    * Comply with regulatory requirements
    The organization has not experienced any reportable breaches but wants to be prepared if a breach occurs in the future. Which of the following is the best way for the organization to prepare?
  • CAS-005 Exam Question 94

    During DAST scanning, applications are consistently reporting code defects in open-source libraries that were used to build web applications. Most of the code defects are from using libraries with known vulnerabilities. The code defects are causing product deployment delays. Which of the following is the best way to uncover these issues earlier in the life cycle?
  • CAS-005 Exam Question 95

    A security engineer is given the following requirements:
    * An endpoint must only execute Internally signed applications
    * Administrator accounts cannot install unauthorized software.
    * Attempts to run unauthorized software must be logged
    Which of the following best meets these requirements?