ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 69 - CAS-004 discussion

Report
Export

A Chief information Security Officer (CISO) is developing corrective-action plans based on the following from a vulnerability scan of internal hosts:

Which of the following MOST appropriate corrective action to document for this finding?

A.
The product owner should perform a business impact assessment regarding the ability to implement a WAF.
Answers
A.
The product owner should perform a business impact assessment regarding the ability to implement a WAF.
B.
The application developer should use a static code analysis tool to ensure any application code is not vulnerable to buffer overflows.
Answers
B.
The application developer should use a static code analysis tool to ensure any application code is not vulnerable to buffer overflows.
C.
The system administrator should evaluate dependencies and perform upgrade as necessary.
Answers
C.
The system administrator should evaluate dependencies and perform upgrade as necessary.
D.
The security operations center should develop a custom IDS rule to prevent attacks buffer overflows against this server.
Answers
D.
The security operations center should develop a custom IDS rule to prevent attacks buffer overflows against this server.
Suggested answer: A
asked 02/10/2024
Mauro Daniele
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first