exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 199 discussion

Actual exam question from CompTIA's CAS-004
Question #: 199
Topic #: 1
[All CAS-004 Questions]

A security analyst discovered that a database administrator's workstation was compromised by malware. After examining the logs, the compromised workstation was observed connecting to multiple databases through ODBC. The following query behavior was captured:



Assuming this query was used to acquire and exfiltrate data, which of the following types of data was compromised, and what steps should the incident response plan contain?

  • A. Personal health information; Inform the human resources department of the breach and review the DLP logs.
  • B. Account history; Inform the relationship managers of the breach and create new accounts for the affected users.
  • C. Customer IDs; Inform the customer service department of the breach and work to change the account numbers.
  • D. PAN; Inform the legal department of the breach and look for this data in dark web monitoring.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ServerBrain
8 months, 4 weeks ago
Selected Answer: D
A primary account number (PAN) is the technical term for a payment card number, the series of digits (usually 12 to 19) embossed or encoded on a credit, debit, or prepaid card that identifies the issuer and specific account.
upvoted 4 times
...
EAlonso
9 months, 4 weeks ago
D. agreed, this is a legal concern.
upvoted 1 times
...
BadgerTester
1 year, 5 months ago
Selected Answer: C
the question says, "which of the following types of data was compromised, and what steps should the incident response plan contain?" the customer ID was what data was compromised. D does not answer the first half (before the ,) of the question.
upvoted 1 times
...
BiteSize
1 year, 9 months ago
Selected Answer: D
1111-1111-1111-1111 is the laziest credit card regex pull. at least get the starting numbers correct 3=AMEX, 4 = Visa, 5 = MC and 6 = DISCOVER. Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 2 times
...
FoxTrotDG
2 years, 2 months ago
Selected Answer: D
PAN is referring to a primary account number, which is associated with payment cards, like debit and credit cards. Also, the regular expression matches a string of digits that is formatted like a credit card number (four sets of four digits separated by hyphens). The answer is D.
upvoted 3 times
p1s3c
1 year, 11 months ago
the thing that bothers me with D is that the incident response plan would have an action to look for this data in dark web monitoring. For how long? it's like getting robbed and going out into town waiting for the robber to sell your stuff.
upvoted 1 times
...
...
ToneBar
2 years, 2 months ago
Selected Answer: D
If you have to store PAN (Personal Account Numbers) data, then PCI DSS Requirement 3.4 requires that yo render it unreadable and unrecoverable through one of the following methods: One-way hashes based on strong cryptography (has must be of the entire PAN) Truncation (hashing cannot be used to replace the truncated segment of PAN) Index tokens and pads (pads must be securely stored) Strong cryptography with associated key-management processes and procedures
upvoted 2 times
...
FOURDUE
2 years, 2 months ago
Selected Answer: C
IT IS NOT D. that is a personal area network.. does not make sense to exfiltrate that. this is talking about accounts where all of those listed expressions are part of the customer id.. Introduction to SQL REGEXP A regular expression in standard query language (SQL) is a special rule that is used to define or describe a search pattern or characters that a particular expression can hold. For example, a phone number can only have 10 digits, so in order to check if a string of numbers is a phone number or not, we can create a regular expression for it. It is an in-built specification supported in almost all SQL databases. Regular expressions are very helpful as they let us place multiple lines of code or information in just 1 line. It is particularly helpful in SQL databases when we want to perform validation tasks like if the information provided is a valid PIN code, Contact No, email address, etc. Regular expressions also help in pattern matching or searching the database. https://www.educba.com/sql-regexp/
upvoted 1 times
FoxTrotDG
2 years, 2 months ago
PAN also stands for Primary Account Number. It's a unique number found on payment cards like debit and credit cards that identifies the card issuer and the cardholder account that is linked to that specific card.
upvoted 4 times
...
FOURDUE
2 years, 2 months ago
also, i think that if it were PHI there would be other security measures in place to mask the data.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago