CAS-005 Exam Question 111

A security analyst is reviewing the following authentication logs:

Which of the following should the analyst do first?
  • CAS-005 Exam Question 112

    During a recentsecurity event, access from thenon-production environment to the production environmentenabledunauthorized usersto:
    Installunapproved software
    Makeunplanned configuration changes
    During theinvestigation, the following findings were identified:
    Several new users were added in bulkby theIAM team
    Additionalfirewalls and routerswere recently added
    Vulnerability assessmentshave been disabled formore than 30 days
    Theapplication allow listhas not been modified intwo weeks
    Logs were unavailablefor various types of traffic
    Endpoints have not been patchedinover ten days
    Which of the following actions would most likely need to be taken toensure proper monitoring?(Select two)
  • CAS-005 Exam Question 113

    A security engineer needs to remediate a SWEET32 vulnerability in an OpenSSH-based application and review existing configurations. Which of the following should the security engineer do? (Select two.)
  • CAS-005 Exam Question 114

    An organization wants to manage specialized endpoints and needs a solution that provides the ability to
    * Centrally manage configurations
    * Push policies.
    * Remotely wipe devices
    * Maintain asset inventory
    Which of the following should the organization do to best meet these requirements?
  • CAS-005 Exam Question 115

    A company implemented a NIDS and a NIPS on the most critical environments. Since this implementation, the company has been experiencing network connectivity issues. Which of the following should the security architect recommend for a new NIDS/NIPS implementation?