CompTIA SecurityX Certification Exam CAS-004 Question # 21 Topic 3 Discussion

CompTIA SecurityX Certification Exam CAS-004 Question # 21 Topic 3 Discussion

CAS-004 Exam Topic 3 Question 21 Discussion:
Question #: 21
Topic #: 3

A Chief information Security Officer (CISO) is developing corrective-action plans based on the following from a vulnerability scan of internal hosts:

CAS-004 Question 21

Which of the following MOST appropriate corrective action to document for this finding?


A.

The product owner should perform a business impact assessment regarding the ability to implement a WAF.


B.

The application developer should use a static code analysis tool to ensure any application code is not vulnerable to buffer overflows.


C.

The system administrator should evaluate dependencies and perform upgrade as necessary.


D.

The security operations center should develop a custom IDS rule to prevent attacks buffer overflows against this server.


Get Premium CAS-004 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.