A high-severity vulnerability was found on a web application and introduced to the enterprise. The vulnerability could allow an unauthorized user to utilize an open- source library to view privileged user information. The enterprise is unwilling to accept the risk, but the developers cannot fix the issue right away.Which of the following should be implemented to reduce the risk to an acceptable level until the issue can be fixed?
Answer(s): C
https://www.microfocus.com/en-us/what-is/sast
A security analyst discovered that the company's WAF was not properly configured. The main web server was breached, and the following payload was found in one of the malicious requests:Which of the following would BEST mitigate this vulnerability?
Answer(s): B
https://hdivsecurity.com/owasp-xml-external-entities-xxe
A university issues badges through a homegrown identity management system to all staff and students. Each week during the summer, temporary summer school students arrive and need to be issued a badge to access minimal campus resources. The security team received a report from an outside auditor indicating the homegrown system is not consistent with best practices in the security field and leaves the institution vulnerable.Which of the following should the security team recommend FIRST?
Answer(s): A
A customer reports being unable to connect to a website at www.test.com to consume services. The customer notices the web application has the following published cipher suite:Which of the following is the MOST likely cause of the customer's inability to connect?
https://security.stackexchange.com/questions/23383/ssh-key-type-rsa-dsa-ecdsa-are-there-easy-answers-for-which-to-choose-when
An IT administrator is reviewing all the servers in an organization and notices that a server is missing crucial practice against a recent exploit that could gain root access.Which of the following describes the administrator's discovery?
https://www.beyondtrust.com/blog/entry/privilege-escalation-attack-defense-explained
Post your Comments and Discuss CompTIA CAS-004 exam dumps with other Community members:
Fatima Commented on January 03, 2025 The purchase and download is very streamlined. I was able to quickly pay and download my course content. I have now started preparing. Once I finish my exam I will share my experience of the exam. EUROPEAN UNION
michrle23 Commented on December 28, 2024 The purchase and download is very streamlined. I was able to quickly pay and download my course content. I have now started preparing. Once I finish my exam I will share my experience of the exam. PAKISTAN
Sysadmin Commented on April 22, 2024 How can you report incorrect answers? #27 is incorrect. First and foremost is always stop the spread, and then access the damage. UNITED STATES
Gord Commented on March 19, 2024 I hardly submit reivews... but the team at Free-Braindumps.com really deserve one. They are super professional and the quality of their study guides are good. I highly recommend it anyone preparing for their exams. UNITED KINGDOM
Change Commented on December 11, 2023 Are some answers wrong UNITED STATES
makeel Commented on December 10, 2023 the questions are the same exist of another website Anonymous
SecPro Commented on October 29, 2023 Great dumps, helped me pass the exam. Anonymous
9eagles Commented on April 07, 2023 on question 10 and so far 2 wrong answers as evident in the included reference link. Anonymous