CAS-005 Exam Question 31
A company needs to quickly assess whether software deployed across the company's global corporate network contains specific software libraries. Which of the following best enables the company's SOC to respond quickly when such an assessment is required?
CAS-005 Exam Question 32
An organization found a significant vulnerability associated with a commonly used package in a variety of operating systems. The organization develops a registry of software dependencies to facilitate incident response activities. As part of the registry, the organization creates hashes of packages that have been formally vetted. Which of the following attack vectors does this registry address?
CAS-005 Exam Question 33
During a recent security event, access from the non-production environment to the production environment enabled unauthorized users to install unapproved software and make unplanned configuration changes. During an investigation, the following findings are identified:
* Several new users were added in bulk by the IAM team.
* Additional firewalls and routers were recently added to the network.
* Vulnerability assessments have been disabled for all devices for more than 30 days.
* The application allow list has not been modified in more than two weeks.
* Logs were unavailable for various types of traffic.
* Endpoints have not been patched in more than ten days.
Which of the following actions would most likely need to be taken to ensure proper monitoring is in place within the organization? (Select two)
* Several new users were added in bulk by the IAM team.
* Additional firewalls and routers were recently added to the network.
* Vulnerability assessments have been disabled for all devices for more than 30 days.
* The application allow list has not been modified in more than two weeks.
* Logs were unavailable for various types of traffic.
* Endpoints have not been patched in more than ten days.
Which of the following actions would most likely need to be taken to ensure proper monitoring is in place within the organization? (Select two)
CAS-005 Exam Question 34
An organization has been using self-managed encryption keys rather than the free keys managed by the cloud provider. The Chief Information Security Officer (CISO) reviews the monthly bill and realizes the self-managed keys are more costly than anticipated. Which of the following should the CISO recommend to reduce costs while maintaining a strong security posture?
CAS-005 Exam Question 35
A company is moving several of its systems to a multicloud environment and wants to automate the creation of the new servers using a standard image. Which of the following should the company implement to best support this goal?
