CAS-001 Exam Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 10 of 11.
- Question #460Technical Integration of Enterprise Components
Two universities are making their 802.11n wireless networks available to the other university's students. The infrastructure will pass the student's credentials back to the home sc...
EAP-PEAPRADIUS federationwireless security802.1X - Question #461Enterprise Security
A company has decided to move to an agile software development methodology. The company gives all of its developers security training. After a year of agile, a management review fi...
agile developmentSDLC securitysprint planningsecurity requirements - Question #462Enterprise Security
A system administrator has a responsibility to maintain the security of the video teleconferencing system. During a self-audit of the video teleconferencing room, the administrator...
Bluetooth securityRF emanationwireless securityphysical security - Question #463Enterprise Security
A security engineer is a new member to a configuration board at the request of management. The company has two new major IT projects starting this year and wants to plan security i...
security assessmentRMFsecurity categorizationsecurity control baseline - Question #464Research and Analysis
A security manager is collecting RFQ, RFP, and RFI publications to help identify the technology trends which a government will be moving towards in the future. This information is...
OSINTdata aggregationintelligence gatheringcompetitive intelligence - Question #465Technical Integration of Enterprise Components
As a cost saving measure, a company has instructed the security engineering team to allow all consumer devices to be able to access the network. They have asked for recommendations...
MDMMEAPmobile securityBYOD - Question #466Integration of Computing, Communications and Business Disciplines
A company uses a custom Line of Business (LOB) application to facilitate all back-end manufacturing control. Upon investigation, it has been determined that the database used by th...
vendor lock-inproprietary formatsdata extractionoperational risk - Question #467Technical Integration of Enterprise Components
An asset manager is struggling with the best way to reduce the time required to perform asset location activities in a large warehouse. A project manager indicated that RFID might...
RFID securityasset trackingencryption limitationswireless technology - Question #468Research and Analysis
Ann, a systems engineer, is working to identify an unknown node on the corporate network. To begin her investigative work, she runs the following nmap command string: user@hostname...
nmapOS fingerprintingport analysisnetwork reconnaissance - Question #469Research and Analysis
A security analyst is tasked to create an executive briefing, which explains the activity and motivation of a cyber adversary. Which of the following is the MOST important content...
threat intelligencethreat actorsexecutive communicationimpact analysis - Question #470Technical Integration of Enterprise Components
A security engineer has inherited an authentication project which integrates 1024-bit PKI certificates into the company infrastructure and now has a new requirement to integrate 20...
PKIcertificate managementproject maintainabilitycryptographic migration - Question #471Technical Integration of Enterprise Components
A company has migrated its data and application hosting to a cloud service provider (CSP). To meet its future needs, the company considers an IdP. Why might the company want to sel...
IdPCSPcircle of trustidentity federation - Question #472Enterprise Security
An internal committee comprised of the facilities manager, the physical security manager, the network administrator, and a member of the executive team has been formed to address a...
physical securitymantrapbiometric accessdata center security - Question #473Technical Integration of Enterprise Components
During a recent audit of servers, a company discovered that a network administrator, who required remote access, had deployed an unauthorized remote access application that communi...
remote accessSSL VPNSAML federationunauthorized software - Question #474Integration of Computing, Communications and Business Disciplines
A company wishes to purchase a new security appliance. A security administrator has extensively researched the appliances, and after presenting security choices to the company's ma...
procurementRFQvendor managementacquisition process - Question #475Technical Integration of Enterprise Components
A small retail company recently deployed a new point of sale (POS) system to all 67 stores. The core of the POS is an extranet site, accessible only from retail stores and the corp...
UTMsplit-tunnel VPNnetwork performancePOS security - Question #476Integration of Computing, Communications and Business Disciplines
Executive management is asking for a new manufacturing control and workflow automation solution. This application will facilitate management of proprietary information and closely...
SaaS integrationcloud securitydata governancerisk analysis - Question #477Enterprise Security
News outlets are beginning to report on a number of retail establishments that are experiencing payment card data breaches. The data exfiltration is enabled by malware on a comprom...
application whitelistingmalware protectionPOS securitythreat detection - Question #478Enterprise Security
The Chief Information Security Officer (CISO) is asking for ways to protect against zero-day exploits. The CISO is concerned that an unrecognized threat could compromise corporate...
zero-day exploitsbehavior-based IPSthreat intelligence feedsunknown threats - Question #479Research and Analysis
A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture with regard to targeted attacks. Which of the f...
threat intelligenceindustry threat feedssecurity posturetargeted attacks - Question #480Integration of Computing, Communications and Business Disciplines
The sales team is considering the deployment of a new CRM solution within the enterprise. The IT and Security teams are members of the project; however, neither team has expertise...
vendor selectionRFP processproject managementdue diligence - Question #481Enterprise Security
A security administrator notices a recent increase in workstations becoming compromised by malware. Often, the malware is delivered via drive-by downloads, from malware hosting web...
drive-by downloadscontent filteringmalware preventionweb gateway - Question #482Integration of Computing, Communications and Business Disciplines
The helpdesk manager wants to find a solution that will enable the helpdesk staff to better serve company employees who call with computer-related problems. The helpdesk staff is c...
remote desktop sharinghelpdesk toolstelecommuter supportcollaboration - Question #483Research and Analysis
A security manager has started a new job and has identified that a key application for a new client does not have an accreditation status and is currently not meeting the complianc...
accreditationSRTMrisk assessmentcompliance - Question #484Integration of Computing, Communications and Business Disciplines
A security administrator was recently hired in a start-up company to represent the interest of security and to assist the network team in improving security in the company. The sal...
security governancestakeholder communicationFAQsecurity awareness - Question #485Integration of Computing, Communications and Business Disciplines
The Chief Information Officer (CIO) is focused on improving IT governance within the organization to reduce system downtime. The CIO has mandated that the following improvements be...
IT governancechange managementrisk profilespolicy alignment - Question #486Enterprise Security
An organization has decided to reduce labor costs by outsourcing back office processing of credit applications to a provider located in another country. Data sovereignty and privac...
data sovereigntyDLPremote desktop controlssession security - Question #487Integration of Computing, Communications and Business Disciplines
A company has received the contract to begin developing a new suite of software tools to replace an aging collaboration solution. The original collaboration solution has been in pl...
SDLCsoftware development methodologyagilerisk analysis - Question #488Technical Integration of Enterprise Components
The manager of the firewall team is getting complaints from various IT teams that firewall changes are causing issues. Which of the following should the manager recommend to BEST a...
firewall change managementchange controlteam communicationoperational process - Question #489Enterprise Security
An intruder was recently discovered inside the data center, a highly sensitive area. To gain access, the intruder circumvented numerous layers of physical and electronic security m...
physical securitydata center accessintrusion preventionfacility controls - Question #490Research and Analysis
The helpdesk department desires to roll out a remote support application for internal use on all company computers. This tool should allow remote desktop sharing, system log gather...
remote support toolsvendor assessmentaccountability controlsrisk review - Question #491Integration of Computing, Communications and Business Disciplines
A software development manager is taking over an existing software development project. The team currently suffers from poor communication, and this gap is resulting in an above av...
agile methodologydaily stand-upSDLCteam communication - Question #492Integration of Computing, Communications and Business Disciplines
A software development manager is taking over an existing software development project. The team currently suffers from poor communication due to a long delay between requirements...
waterfall methodologySDLCrequirements delaysecurity bugs - Question #494Enterprise Security
A security manager has received the following email from the Chief Financial Officer (CFO): "While I am concerned about the security of the proprietary financial data in our ERP ap...
remote access policyERP securitypolicy governancetelecommuting - Question #495Technical Integration of Enterprise Components
A UNIX administrator notifies the storage administrator that extra LUNs can be seen on a UNIX server. The LUNs appear to be NTFS file systems. Which of the following MOST likely ha...
SANHBA allocationLUN maskingstorage administration - Question #496Technical Integration of Enterprise Components
Company ABC's SAN is nearing capacity, and will cause costly downtimes if servers run out disk space. Which of the following is a more cost effective alternative to buying a new SA...
SAN capacitydeduplicationstorage optimizationcost management - Question #497Technical Integration of Enterprise Components
A new internal network segmentation solution will be implemented into the enterprise that consists of 200 internal firewalls. As part of running a pilot exercise, it was determined...
network segmentationfirewall deploymentcontrol effectivenesscomplexity analysis - Question #498Enterprise Security
select id, firstname, lastname from authors User input= firstname= Hack;man lastname=Johnson Which of the following types of attacks is the user attempting?
SQL injectioninjection attacksweb application securityinput validation - Question #499Technical Integration of Enterprise Components
Three companies want to allow their employees to seamlessly connect to each other's wireless corporate networks while keeping one consistent wireless client configuration. Each com...
802.1xRADIUS federationEAP-PEAPwireless authentication - Question #500Research and Analysis
A government agency considers confidentiality to be of utmost importance and availability issues to be of least importance. Knowing this, which of the following correctly orders va...
CIA triadvulnerability prioritizationconfidentialityrisk analysis - Question #501Integration of Computing, Communications and Business Disciplines
The Chief Executive Officer (CEO) of a large prestigious enterprise has decided to reduce business costs by outsourcing to a third party company in another country. Functions to be...
outsourcing riskthird-party data handlingintellectual propertyregulatory compliance - Question #502Technical Integration of Enterprise Components
An organization has just released a new mobile application for its customers. The application has an inbuilt browser and native application to render content from existing websites...
SSO token storagemobile securityOAuth/token securityREST API authentication - Question #503Technical Integration of Enterprise Components
A bank provides single sign on services between its internally hosted applications and externally hosted CRM. The following sequence of events occurs: 1.The banker accesses the CRM...
SAML 2.0federated SSOservice provider initiatedidentity federation - Question #504Enterprise Security
A corporation implements a mobile device policy on smartphones that utilizes a white list for allowed applications. Recently, the security administrator notices that a consumer clo...
mobile device managementcloud storage riskdata exfiltrationapplication whitelist - Question #505Enterprise Security
A security policy states that all applications on the network must have a password length of eight characters. There are three legacy applications on the network that cannot meet t...
risk exceptionlegacy systemspolicy compliancerisk management process - Question #506Technical Integration of Enterprise Components
A systems administrator establishes a CIFS share on a Unix device to share data to windows systems. The security authentication on the windows domain is set to the highest level. W...
CIFSNTLMv2cross-platform authenticationWindows domain security - Question #507Enterprise Security
Company XYZ provides hosting services for hundreds of companies across multiple industries including healthcare, education, and manufacturing. The security architect for company XY...
multi-tenant virtualizationdata separationPII regulatory compliancehosting security - Question #508Technical Integration of Enterprise Components
A security architect is designing a new infrastructure using both type 1 and type 2 virtual machines. In addition to the normal complement of security controls (e.g. antivirus, hos...
vTPMcryptographic key storagevirtualization securitycode signing - Question #509Technical Integration of Enterprise Components
A Linux security administrator is attempting to resolve performance issues with new software installed on several baselined user systems. After investigating, the security administ...
SELinuxmandatory access controltrusted OSenforcing mode policy - Question #510Enterprise Security
A security auditor is conducting an audit of a corporation where 95% of the users travel or work from non-corporate locations a majority of the time. While the employees are away f...
full disk encryptionPII protectionmobile workforcedata at rest