ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 391 - CAS-004 discussion

Report
Export

A security engineer is trying to identify instances of a vulnerability in an internally developed line of business software. The software is hosted at the company's internal data center. Although a standard vulnerability definition does not exist, the identification and remediation results should be tracked in the company's vulnerability management system. Which of the following should the engineer use to identify this vulnerability?

A.
SIEM
Answers
A.
SIEM
B.
CASB
Answers
B.
CASB
C.
SCAP
Answers
C.
SCAP
D.
OVAL
Answers
D.
OVAL
Suggested answer: C

Explanation:

The Security Content Automation Protocol (SCAP) is a method for using specific standards to enable automated vulnerability management, measurement, and policy compliance evaluation. Using SCAP can help to identify vulnerabilities, including those without standard definitions, and ensure they are tracked and managed effectively.

asked 02/10/2024
Reece Scarley
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first