CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 39: CAS-004: CompTIA Advanced Security Practitioner (CASP+) CAS-004

A high-severity vulnerability was found on a web application and introduced to the enterprise. The vulnerability could allow an unauthorized user to utilize an open- source library to view privileged user information. The enterprise is unwilling to accept the risk, but the developers cannot fix the issue right away. W…

Nội dung câu hỏi

A high-severity vulnerability was found on a web application and introduced to the enterprise. The vulnerability could allow an unauthorized user to utilize an open- source library to view privileged user information. The enterprise is unwilling to accept the risk, but the developers cannot fix the issue right away. Which of the following should be implemented to reduce the risk to an acceptable level until the issue can be fixed?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Scan the code with a static code analyzer, change privileged user passwords, and provide security training.
  2. B. Change privileged usernames, review the OS logs, and deploy hardware tokens.
  3. C. Implement MFA, review the application logs, and deploy a WAF. — đáp án hiện tại
  4. D. Deploy a VPN, configure an official open-source library repository, and perform a full application review for vulnerabilities.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề