A security engineer needs to ensure production containers are automatically scanned for vulnerabilities before they are accepted into the production environment.
Which of the following should the engineer use to automatically incorporate vulnerability scanning on every commit?
A. Code repositoryAn ASIC manufacturer wishing to best reduce downstream supply chain risk can provide validation instructions for consumers that:
A. Leverage physically uncloneable functions.A new mandate by the corporate security team requires that all endpoints must meet a security baseline before accessing the corporate network. All servers and desktop computers are scanned by the dedicated internal scanner appliance installed in each subnet. However, remote worker laptops do not access the network regularly. Which of the following is the BEST option for the security team to ensure remote worker laptops are scanned before being granted access to the corporate network?
A. Implement network access control to perform host validation of installed patches.The principal security analyst for a global manufacturer is investigating a security incident related to abnormal behavior in the ICS network. A controller was restarted as part of the troubleshooting process, and the following issue was identified
when the controller was restarted:
SECURE BOOT FAILED:
FIRMWARE MISMATCH EXPECTED 0xFDC479 ACTUAL 0x79F31B
During the investigation, this modified firmware version was identified on several other controllers at the site. The official vendor firmware versions do not have this checksum. Which of the following stages of the MITRE ATTandCK framework for
ICS includes this technique?
A. EvasionA development team needs terminal access to preproduction servers to verify settings and enter purchased license keys. To address the team's needs, the security administrator implements the following requirements:
1.Only trusted accounts can access the preproduction servers.
2.Developers cannot access the preproduction servers directly from their workstations.
3.The trusted accounts should only have access to specific preproduction servers.
Which of the following are necessary to fulfill the security requirements? (Select two).
A. SSL VPNA company moved its on-premises services to the cloud. Although a recent audit verified that data throughout the cloud service is properly classified and documented, other systems are unable to act or filter based on this information. Which of the following should the company deploy to allow other cloud-based systems to consume this information?
A. Data mappingA security engineer needs to implement a cost-effective authentication scheme for a new web-based application that requires:
1.Rapid authentication
2.Flexible authorization
3.Ease of deployment
4.Low cost but high functionality
Which of the following approaches best meets these objectives?
A. KerberosA security architect is advising the application team to implement the following controls in the application before it is released:
1.Least privilege
2.Blocklist input validation for the following characters: \<>;, ="#+
Based on the requirements, which of the following attacks is the security architect trying to prevent?
A. XML injectionA security analyst is researching containerization concepts for an organization. The analyst is concerned about potential resource exhaustion scenarios on the Docker host due to a single application that is overconsuming available resources. Which of the following core Linux concepts BEST reflects the ability to limit resource allocation to containers?
A. Union filesystem overlayA company is migrating its data center to the cloud. Some hosts had been previously isolated, but a risk assessment convinced the engineering team to reintegrate the systems. Because the systems were isolated, the risk associated with
vulnerabilities was low.
Which of the following should the security team recommend be performed before migrating these servers to the cloud?
A. Performing patching and hardeningNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.