exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 489 discussion

Actual exam question from CompTIA's CAS-004
Question #: 489
Topic #: 1
[All CAS-004 Questions]

A security engineer is trying to identify instances of a vulnerability in an internally developed line of business software. The software is hosted at the company's internal data center. Although a standard vulnerability definition does not exist, the identification and remediation results should be tracked in the company's vulnerability management system. Which of the following should the engineer use to identify this vulnerability?

  • A. SIEM
  • B. CASB
  • C. SCAP
  • D. OVAL
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Kokoh23
1 day, 6 hours ago
Selected Answer: D
If there is no Vulnerability definition SCAP will not make a finding. (False Negative) So the Security Administrator needs to use OVAL to write a custom definition. Then run SCAP.
upvoted 1 times
...
231354b
5 days, 14 hours ago
Selected Answer: D
Given the scenario of identifying vulnerabilities in internally developed software without a standard vulnerability definition, **OVAL (Open Vulnerability and Assessment Language)** would be the most applicable. OVAL allows for the creation of custom definitions and enables the engineer to specify the exact conditions that represent the vulnerability in the software. This customization is critical for tracking and remediating non-standard vulnerabilities in the company's vulnerability management system. SCAP is also valuable, but OVAL within SCAP provides the flexibility needed for this particular situation. So, focusing on OVAL would be the most effective approach.
upvoted 1 times
...
grelaman
2 months, 1 week ago
Selected Answer: D
OVAL is an open standard for defining and sharing information about computer vulnerabilities, configuration issues, and patch statuses. It allows you to create standardized checks for vulnerabilities, which can be used to integrate into vulnerability management systems to identify and assess specific vulnerabilities. - Custom Vulnerability Definitions: Allows the creation of custom vulnerability definitions tailored to the organization's specific software. - Integration with Vulnerability Management Systems: OVAL definitions can be consumed by vulnerability scanners and management systems to detect the presence of vulnerabilities. While SCAP provides a framework for using standardized vulnerability definitions, it relies on existing standards like OVAL for creating and defining those vulnerabilities. Since a standard vulnerability definition does not exist, SCAP alone is insufficient without OVAL.
upvoted 1 times
...
Bright07
2 months, 2 weeks ago
Ans D. The best option for the engineer to identify the vulnerability in the internally developed software would be: D. OVAL. OVAL (Open Vulnerability and Assessment Language) is designed to provide a standardized method for representing system details and identifying vulnerabilities, making it suitable for tracking and remediation in this context.
upvoted 2 times
...
HereToStudy
2 months, 3 weeks ago
Selected Answer: C
SCAP provides a standardized approach to vulnerability identification and remediation, allowing the engineer to track the results in the vulnerability management system, even for custom or internally developed software.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago