Free CAS-004 Exam Braindumps (page: 17)

Page 17 of 159

An organization recently experienced a ransomware attack. The security team leader is concerned about the attack reoccurring. However, no further security measures have been implemented.
Which of the following processes can be used to identify potential prevention recommendations?

  1. Detection
  2. Remediation
  3. Preparation
  4. Recovery

Answer(s): C



Some end users of an e-commerce website are reporting a delay when browsing pages. The website uses TLS 1.2. A security architect for the website troubleshoots by connecting from home to the website and capturing traffic via Wireshark. The security architect finds that the issue is the time required to validate the certificate. Which of the following solutions should the security architect recommend?

  1. Adding more nodes to the web server clusters
  2. Changing the cipher algorithm used on the web server
  3. Implementing OCSP stapling on the server
  4. Upgrading to TLS 1.3

Answer(s): C



A security engineer was auditing an organization's current software development practice and discovered that multiple open-source libraries were Integrated into the organization's software. The organization currently performs SAST and DAST on the software it develops.
Which of the following should the organization incorporate into the SDLC to ensure the security of the open-source libraries?

  1. Perform additional SAST/DAST on the open-source libraries.
  2. Implement the SDLC security guidelines.
  3. Track the library versions and monitor the CVE website for related vulnerabilities.
  4. Perform unit testing of the open-source libraries.

Answer(s): C


Reference:

https://www.whitesourcesoftware.com/resources/blog/application-security-best-practices/



A security analyst is investigating a possible buffer overflow attack. The following output was found on a user's workstation: graphic.linux_randomization.prg
Which of the following technologies would mitigate the manipulation of memory segments?

  1. NX bit
  2. ASLR
  3. DEP
  4. HSM

Answer(s): B


Reference:

http://webpages.eng.wayne.edu/~fy8421/19sp-csc5290/labs/lab2-instruction.pdf
(3)






Post your Comments and Discuss CompTIA CAS-004 exam with other Community members:

CAS-004 Exam Discussions & Posts