CAS-005 Exam Question 96

A security engineer is developing a solution to meet the following requirements?
* All endpoints should be able to establish telemetry with a SIEM.
* All endpoints should be able to be integrated into the XDR platform.
* SOC services should be able to monitor the XDR platform
Which of the following should the security engineer implement to meet the requirements?
  • CAS-005 Exam Question 97

    After several companies in the financial industry were affected by a similar incident, they shared information about threat intelligence and the malware used for exploitation. Which of the following should the companies do to best indicate whether the attacks are being conducted by the same actor?
  • CAS-005 Exam Question 98

    A company detects suspicious activity associated with inbound connections. Security detection tools are unable to categorize this activity. Which of the following is the best solution to help the company overcome this challenge?
  • CAS-005 Exam Question 99

    A security engineer discovers that some legacy systems are still in use or were not properly decommissioned. After further investigation, the engineer identifies that an unknown and potentially malicious server is also sending emails on behalf of the company. The security engineer extracts the following data for review:

    Which of the following actions should the security engineer take next? (Select two).
  • CAS-005 Exam Question 100

    An external threat actor attacks public infrastructure providers. In response to the attack and during follow-up activities, various providers share information obtained during response efforts. After the attack, energy sector companies share their status and response data:
    Company
    SIEM
    UEBA
    DLP
    ISAC Member
    TIP Integration
    Time to Detect
    Time to Respond
    1
    Yes
    No
    Yes
    Yes
    Yes
    10 minutes
    20 minutes
    2
    Yes
    Yes
    Yes
    Yes
    No
    20 minutes
    40 minutes
    3
    Yes
    Yes
    No
    No
    Yes
    12 minutes
    24 minutes
    Which of thefollowing is the most important issue to address to defend against future attacks?