A company created an external application for its customers. A security researcher now reports that the application has a serious LDAP injection vulnerability that could be leveraged to bypass authentication and authorization.
Which of the following actions would BEST resolve the issue? (Choose two.)
A. Conduct input sanitization.
B. Patch the OS
C. Use containers.
D. Deploy a WAF.
E. Deploy a reverse proxy
F. Deploy a SIEM.
G. Deploy an IDS.
正解:A,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
A company wants to improve the security of its web applications that are running on in-house servers A risk assessment has been performed and the following capabilities are desired:
* Terminate SSL connections at a central location
* Manage both authentication and authorization for incoming and outgoing web service calls
* Advertise the web service API
* Implement DLP and anti-malware features
Which of the following technologies will be the BEST option?
A. WAF
B. API gateway
C. XML gateway
D. ESB gateway
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
A company requires a task to be carried by more than one person concurrently. This is an example of:
A. separation of d duties.
B. dual control
C. least privilege
D. job rotation
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
A company with customers in the United States and Europe wants to ensure its content is delivered to end users with low latency. Content includes both sensitive and public information. The company's data centers are located on the West Coast of the United States. Users on the East Coast of the United States and users in Europe are experiencing slow application response. Which of the following would allow the company to improve application response quickly?
A. Installing reverse caching proxies in both data centers and implementing proxy auto scaling
B. Using colocation services in regions where the application response is slow
C. Using HTTPS to serve sensitive content and HTTP for public content
D. Implementing a CDN and forcing all traffic through the CDN
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
An organization needs to classify its systems and data in accordance with external requirements. Which of the following roles is best qualified to perform this task?
A. Systems administrator
B. Data owner
C. Data processor
D. Data custodian
E. Data steward
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
A SOC analyst received an alert about a potential compromise and is reviewing the following SIEM logs:

Which of the following is the most appropriate action for the SOC analyst to recommend?
A. Creating HIPS and NIPS rules to prevent logins
B. Alerting JDoe about the potential account compromise
C. Isolating laptop314 from the network
D. Disabling account JDoe to prevent further lateral movement
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
Aizawa -
仕事に忙しいので、私は勉強する時間は少ないです。しかし、CAS-004問題集を利用し、問題の答えを覚えると、CAS-004試験に合格しました。