ExamGecko
Home / CompTIA / CAS-004 / List of questions
Ask Question

CompTIA CAS-004 Practice Test - Questions Answers, Page 47

Add to Whishlist

List of questions

Question 461

Report Export Collapse

Which of the following provides the best solution for organizations that want to securely back up the MFA seeds for its employees in a central, offline location with minimal management overhead?

Become a Premium Member for full access
  Unlock Premium Member

Question 462

Report Export Collapse

A common industrial protocol has the following characteristics:

* Provides for no authentication/security

* Is often implemented in a client/server relationship

* Is implemented as either RTU or TCP/IP

Which of the following is being described?

Become a Premium Member for full access
  Unlock Premium Member

Question 463

Report Export Collapse

A security researcher identified the following messages while testing a web application:

CompTIA CAS-004 image Question 463 94431 10022024175035000000

Which of the following should the researcher recommend to remediate the issue?

Become a Premium Member for full access
  Unlock Premium Member

Question 464

Report Export Collapse

During a software assurance assessment, an engineer notices the source code contains multiple instances of strcpy. which does not verify the buffer length. Which of the following solutions should be integrated into the SDLC process to reduce future risks?

Become a Premium Member for full access
  Unlock Premium Member

Question 465

Report Export Collapse

An organization developed a containerized application. The organization wants to run the application in the cloud and automatically scale it based on demand. The security operations team would like to use container orchestration but does not want to assume patching responsibilities. Which of the following service models best meets these requirements?

Become a Premium Member for full access
  Unlock Premium Member

Question 466

Report Export Collapse

A security architect examines a section of code and discovers the following:

CompTIA CAS-004 image Question 466 94434 10022024175035000000

Which of the following changes should the security architect require before approving the code for release?

Become a Premium Member for full access
  Unlock Premium Member

Question 467

Report Export Collapse

A control systems analyst is reviewing the defensive posture of engineering workstations on the shop floor. Upon evaluation, the analyst makes the following observations:

* Unsupported, end-of-life operating systems were still prevalent on the shop floor.

* There are no security controls for systems with supported operating systems.

* There is little uniformity of installed software among the workstations.

Which of the following would have the greatest impact on the attack surface?

Become a Premium Member for full access
  Unlock Premium Member

Question 468

Report Export Collapse

A DNS forward lookup zone named complia.org must:

* Ensure the DNS is protected from on-path attacks.

* Ensure zone transfers use mutual authentication and are authenticated and negotiated.

Which of the following should the security architect configure to meet these requirements? (Select two).

Become a Premium Member for full access
  Unlock Premium Member

Question 469

Report Export Collapse

A company recently migrated its critical web application to a cloud provider's environment. As part of the company's risk management program, the company intends to conduct an external penetration test. According to the scope of work and the rules of engagement, the penetration tester will validate the web application's security and check for opportunities to expose sensitive company information in the newly migrated cloud environment. Which of the following should be the first consideration prior to engaging in the test?

Become a Premium Member for full access
  Unlock Premium Member

Question 470

Report Export Collapse

A security team is concerned with attacks that are taking advantage of return-oriented programming against the company's public-facing applications. Which of the following should the company implement on the public-facing servers?

Become a Premium Member for full access
  Unlock Premium Member
Total 578 questions
Go to page: of 58
Search

Related questions