ExamGecko
Home / CompTIA / CAS-004 / List of questions
Ask Question

CompTIA CAS-004 Practice Test - Questions Answers, Page 21

Add to Whishlist

List of questions

Question 201

Report Export Collapse

A company wants to quantify and communicate the effectiveness of its security controls but must establish measures. Which of the following is MOST likely to be included in an effective assessment roadmap for these controls?

Become a Premium Member for full access
  Unlock Premium Member

Question 202

Report Export Collapse

A company launched a new service and created a landing page within its website network for users to access the service. Per company policy, all websites must utilize encryption for any authentication pages. A junior network administrator proceeded to use an outdated procedure to order new certificates. Afterward, customers are reporting the following error when accessing a new web page: NET:ERR_CERT_COMMON_NAME_INVALID. Which of the following BEST describes what the administrator should do NEXT?

Become a Premium Member for full access
  Unlock Premium Member

Question 203

Report Export Collapse

An enterprise is undergoing an audit to review change management activities when promoting code to production. The audit reveals the following:

* Some developers can directly publish code to the production environment.

* Static code reviews are performed adequately.

* Vulnerability scanning occurs on a regularly scheduled basis per policy.

Which of the following should be noted as a recommendation within the audit report?

Become a Premium Member for full access
  Unlock Premium Member

Question 204

Report Export Collapse

An organization requires a contractual document that includes

* An overview of what is covered

* Goals and objectives

* Performance metrics for each party

* A review of how the agreement is managed by all parties

Which of the following BEST describes this type of contractual document?

Become a Premium Member for full access
  Unlock Premium Member

Question 205

Report Export Collapse

Based on PCI DSS v3.4, One Particular database field can store data, but the data must be unreadable. which of the following data objects meets this requirement?

Become a Premium Member for full access
  Unlock Premium Member

Question 206

Report Export Collapse

A company just released a new video card. Due to limited supply and high demand, attackers are employing automated systems to purchase the device through the company's web store so they can resell it on the secondary market. The company's intended customers are frustrated. A security engineer suggests implementing a CAPTCHA system on the web store to help reduce the number of video cards purchased through automated systems. Which of the following now describes the level of risk?

Become a Premium Member for full access
  Unlock Premium Member

Question 207

Report Export Collapse

A developer wants to develop a secure external-facing web application. The developer is looking for an online community that produces tools, methodologies, articles, and documentation in the field of

web-application security Which of the following is the BEST option?

Become a Premium Member for full access
  Unlock Premium Member

Question 208

Report Export Collapse

Which of the following is the BEST disaster recovery solution when resources are running in a cloud environment?

Become a Premium Member for full access
  Unlock Premium Member

Question 209

Report Export Collapse

An organization is assessing the security posture of a new SaaS CRM system that handles sensitive PI I and identity information, such as passport numbers. The SaaS CRM system does not meet the organization's current security standards. The assessment identifies the following:

1) There will be a 520,000 per day revenue loss for each day the system is delayed going into production.

2) The inherent risk is high.

3) The residual risk is low.

4) There will be a staged deployment to the solution rollout to the contact center.

Which of the following risk-handling techniques will BEST meet the organization's requirements?

Become a Premium Member for full access
  Unlock Premium Member

Question 210

Report Export Collapse

A company's finance department acquired a new payment system that exports data to an unencrypted file on the system. The company implemented controls on the file so only appropriate personnel are allowed access. Which of the following risk techniques did the department use in this situation?

Become a Premium Member for full access
  Unlock Premium Member
Total 578 questions
Go to page: of 58
Search

Related questions