Free CAS-004 Exam Braindumps (page: 19)

Page 19 of 159

A company is moving most of its customer-facing production systems to the cloud-facing production systems to the cloud. IaaS is the service model being used.
The Chief Executive Officer is concerned about the type of encryption available and requires the solution must have the highest level of security.
Which of the following encryption methods should the cloud security engineer select during the implementation phase?

  1. Instance-based
  2. Storage-based
  3. Proxy-based
  4. Array controller-based

Answer(s): A



A vulnerability analyst identified a zero-day vulnerability in a company's internally developed software. Since the current vulnerability management system does not have any checks for this vulnerability, an engineer has been asked to create one.
Which of the following would be BEST suited to meet these requirements?

  1. ARF
  2. ISACs
  3. Node.js
  4. OVAL

Answer(s): D



An organization recently started processing, transmitting, and storing its customers' credit card information. Within a week of doing so, the organization suffered a massive breach that resulted in the exposure of the customers' information.
Which of the following provides the BEST guidance for protecting such information while it is at rest and in transit?

  1. NIST
  2. GDPR
  3. PCI DSS
  4. ISO

Answer(s): C


Reference:

https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard



Which of the following is the MOST important security objective when applying cryptography to control messages that tell an ICS how much electrical power to output?

  1. Improving the availability of messages
  2. Ensuring non-repudiation of messages
  3. Enforcing protocol conformance for messages
  4. Assuring the integrity of messages

Answer(s): D






Post your Comments and Discuss CompTIA CAS-004 exam with other Community members:

CAS-004 Exam Discussions & Posts