Discount Offer
Go Back on CAS-004 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99



Pass exam with Dumps4free or we will provide you with three additional months of access for FREE.

CAS-004 Practice Test


Page 10 out of 40 Pages

A Chief Information Officer is considering migrating all company data to the cloud to save
money on expensive SAN storage.
Which of the following is a security concern that will MOST likely need to be addressed
during migration?


A.

Latency


B.

Data exposure


C.

Data loss


D.

Data dispersion





A.
  

Latency



A security engineer at a company is designing a system to mitigate recent setbacks caused
competitors that are beating the company to market with the new products. Several of the
products incorporate propriety enhancements developed by the engineer’s company. The
network already includes a SEIM and a NIPS and requires 2FA for all user access. Which
of the following system should the engineer consider NEXT to mitigate the associated
risks?


A.

DLP


B.

Mail gateway


C.

Data flow enforcement


D.

UTM





A.
  

DLP



A company’s claims processed department has a mobile workforce that receives a large
number of email submissions from personal email addresses. An employees recently
received an email that approved to be claim form, but it installed malicious software on the
employee’s laptop when was opened.


A.

Impalement application whitelisting and add only the email client to the whitelist for
laptop in the claims processing department.


B.

Required all laptops to connect to the VPN before accessing email.


C.

Implement cloud-based content filtering with sandboxing capabilities.


D.

Install a mail gateway to scan incoming messages and strip attachments before they
reach the mailbox.





C.
  

Implement cloud-based content filtering with sandboxing capabilities.



A company’s Chief Information Security Officer is concerned that the company’s proposed
move to the cloud could lead to a lack of visibility into network traffic flow logs within the
VPC.
Which of the following compensating controls would be BEST to implement in this
situation?


A.

EDR


B.

SIEM


C.

HIDS


D.

UEBA





B.
  

SIEM



Reference: https://runpanther.io/cyber-explained/cloud-based-siem-explained/

A company’s employees are not permitted to access company systems while traveling
internationally. The company email system is configured to block logins based on
geographic location, but some employees report their mobile phones continue to sync
email traveling . Which of the following is the MOST likely explanation? (Select TWO.)


A.

Outdated escalation attack


B.

Privilege escalation attack


C.

VPN on the mobile device


D.

Unrestricted email administrator accounts


E.

Chief use of UDP protocols


F.

Disabled GPS on mobile devices





C.
  

VPN on the mobile device



F.
  

Disabled GPS on mobile devices




Page 10 out of 40 Pages
Previous