A company isolated its OT systems from other areas of the corporate network These systems are required to report usage information over the internet to the vendor Which oi the following b*st reduces the risk of compromise or sabotage' (Select two).
A. Encrypting data at rest
B. Implementing a site-to-site IPSec VPN
C. Implementing allow lists
D. Performing boot Integrity checks
E. Executing daily health checks
F. Monitoring network behavior
正解:B,C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
An organization wants to manage specialized endpoints and needs a solution that provides the ability to
* Centrally manage configurations
* Push policies.
* Remotely wipe devices
* Maintain asset inventory
Which of the following should the organization do to best meet these requirements?
A. Configure contextual policy management
B. Deploy a software asset manager
C. Use a configuration management database
D. Implement a mobile device management solution.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
A security analystreviews the following report:

Which of the following assessments is the analyst performing?
A. Organizational
B. Quantitative
C. System
D. Supply chain
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
An organization is developing a disaster recovery plan that requires data to be backed up and available at a moment's notice. Which of the following should the organization consider first to address this requirement?
A. Identify critical business processes and determine associated software and hardware requirements.
B. Implement a change management plan to ensure systems are using the appropriate versions.
C. Design an appropriate warm site for business continuity.
D. Hire additional on-call staff to be deployed if an event occurs.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
During a forensic review of a cybersecurity incident, a security engineer collected a portion of the payload used by an attacker on a comprised web server Given the following portion of the code:

Which of the following best describes this incident?
A. Stored XSS
B. Command injection
C. XSRF attack
D. SQL injection
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
A cloud engineer needs to identify appropriate solutions to:
* Provide secure access to internal and external cloud resources.
* Eliminate split-tunnel traffic flows.
* Enable identity and access management capabilities.
Which of the following solutions arc the most appropriate? (Select two).
A. Federation
B. SD-WAN
C. PAM
D. CASB
E. Microsegmentation
F. SASE
正解:D,F
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
Which of the following best describes the reason PQC preparation is important?
A. To leverage asymmetric encryption for large amounts of data
B. To have larger key lengths available through key stretching
C. To improve encryption performance and speed using lightweight cryptography
D. To protect data against decryption due to increases in computational resource availability
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
An organization currently has IDS, firewall, and DLP systems in place. The systems administrator needs to integrate the tools in the environment to reduce response time. Which of the following should the administrator use?
A. XCCDF
B. CMDB
C. SOAR
D. CWPP
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
佐藤** -
CAS-005問題集は図表が多く、試験対策としてものすごく参考になると思いました。