CAS-001 Exam Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 2 of 11.
- Question #51Integration of Computing, Communications and Business Disciplines
A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the co...
vendor managementoutsourcing riskservice agreementsthird-party governance - Question #52Enterprise Security
Company XYZ has invested an increasing amount in security due to the changing threat landscape. The company is going through a cost cutting exercise and the Chief Financial Officer...
preventative controlsdetective controlscorrective controlssecurity controls framework - Question #53Integration of Computing, Communications and Business Disciplines
There has been a recent security breach which has led to the release of sensitive customer information. As part of improving security and reducing the disclosure of customer data,...
privacy compliancedata handlingsecurity awareness trainingcustomer data protection - Question #54Technical Integration of Enterprise Components
A new malware spreads over UDP Port 8320 and several network hosts have been infected. A new security administrator has determined a possible cause, and the infected machines have...
firewall rulesmalware mitigationexplicit denyUDP filtering - Question #55Enterprise Security
A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situa...
technical controlssecurity policy enforcementDLPaccess monitoring - Question #56Technical Integration of Enterprise Components
A small company has recently placed a newly installed DNS server on the DMZ and wants to secure it by allowing Internet hosts to query the DNS server. Since the company deploys an...
firewall ACLDNS DMZ configurationport assignmentnetwork access control - Question #57Technical Integration of Enterprise Components
An administrator would like to connect a server to a SAN. Which of the following processes would BEST allow for availability and access control?
SAN storageLUN maskingHBA multipathstorage availability - Question #58Technical Integration of Enterprise Components
A company data center provides Internet based access to email and web services. The firewall is separated into four zones: - RED ZONE is an Internet zone - ORANGE ZONE a Web DMZ -...
network security zonesNIPS placementDMZ architecturedefense in depth - Question #59Technical Integration of Enterprise Components
An administrator implements a new PHP application into an existing website and discovers the newly added PHP pages do not work. The rest of the site also uses PHP and is functionin...
SELinuxApache configurationweb application securityLinux mandatory access control - Question #60Technical Integration of Enterprise Components
Company GHI consolidated their network distribution so twelve network VLANs would be available over dual fiber links to a modular L2 switch in each of the company's six IDFs. The I...
STPbridge loopVLAN redundancyLayer 2 security - Question #61Enterprise Security
After a recent outbreak of malware attacks, the Chief Information Officer (CIO) tasks the new security manager with determining how to keep these attacks from reoccurring. The comp...
vulnerability assessmentendpoint securitymalware mitigationHIPS - Question #62Research and Analysis
The Chief Information Officer (CIO) of Company XYZ has returned from a large IT conference where one of the topics was defending against zero day attacks ?specifically deploying th...
patch managementzero-day vulnerabilitiesthird-party risksoftware licensing - Question #63Technical Integration of Enterprise Components
When planning a complex system architecture, it is important to build in mechanisms to secure log information, facilitate audit log reduction, and event correlation. Besides synchr...
SIEM architecturelog managementNTP synchronizationcentralized logging - Question #64Enterprise Security
Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?
continuous monitoringaudit logginglog transferrisk mitigation - Question #65Technical Integration of Enterprise Components
A corporation relies on a server running a trusted operating system to broker data transactions between different security zones on their network. Each zone is a separate domain an...
network segmentationsecurity zonesNIPS placementSAN security - Question #66Technical Integration of Enterprise Components
A system architect has the following constraints from the customer: - Confidentiality, Integrity, and Availability (CIA) are all of equal importance. - Average availability must be...
high availabilityVDICIA triadunified communications - Question #67Technical Integration of Enterprise Components
The security administrator reports that the physical security of the Ethernet network has been breached, but the fibre channel storage network was not breached. Why might this stil...
FCoEiSCSIstorage network securitynetwork convergence - Question #68Research and Analysis
As part of a new wireless implementation, the Chief Information Officer's (CIO's) main objective is to immediately deploy a system that supports the 802.11r standard, which will he...
802.11r standardwireless deploymentfirmware upgradabilitypre-ratification risk - Question #69Integration of Computing, Communications and Business Disciplines
A firm's Chief Executive Officer (CEO) is concerned that its IT staff lacks the knowledge to identify complex vulnerabilities that may exist in the payment system being internally...
grey box testingNDAcode confidentialitysecurity assurance - Question #70Research and Analysis
The security manager is in the process of writing a business case to replace a legacy secure web gateway so as to meet an availability requirement of 99.9% service availability. Ac...
MTBFMTTRavailability calculationSLA - Question #71Enterprise Security
What of the following vulnerabilities is present in the below source code file named `AuthenticatedArea.php'? <html><head><title>AuthenticatedArea</title></head> <? include ("/inc/...
cross-site scriptingXSSPHP input validationweb application security - Question #72Research and Analysis
There have been some failures of the company's customer-facing website. A security engineer has analyzed the root cause to be the WAF. System logs show that the WAF has been down f...
MTTRWAF availabilityincident managementdowntime calculation - Question #73Integration of Computing, Communications and Business Disciplines
To support a software security initiative business case, a project manager needs to provide a cost benefit analysis. The project manager has asked the security consultant to perfor...
ROI calculationcost-benefit analysissecurity investmentsoftware security initiative - Question #74Enterprise Security
During user acceptance testing, the security administrator believes to have discovered an issue in the login prompt of the company's financial system. While entering the username a...
fuzzingapplication testingvulnerability reproductioncrash analysis - Question #75Technical Integration of Enterprise Components
The network administrator has been tracking the cause of network performance problems and decides to take a look at the internal and external router stats. Which of the following s...
QoSIP TOS fieldnetwork performancetraffic prioritization - Question #76Technical Integration of Enterprise Components
A security administrator wants to perform an audit of the company password file to ensure users are not using personal information such as addresses and birthdays as part of their...
password auditingcluster computingcloud provisioningperformance optimization - Question #77Research and Analysis
The security administrator at `company.com' is reviewing the network logs and notices a new UDP port pattern where the amount of UDP port 123 packets has increased by 20% above the...
NTP attacknetwork traffic analysisanomaly detectionprotocol exploitation - Question #78Integration of Computing, Communications and Business Disciplines
A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a...
security policy developmentvendor managementcomplianceregulatory requirements - Question #79Enterprise Security
A Chief Information Security Officer (CISO) has been trying to eliminate some IT security risks for several months. These risks are not high profile but still exist. Furthermore, m...
risk acceptancerisk management strategybudget constraintsresidual risk - Question #80Integration of Computing, Communications and Business Disciplines
The firm's CISO has been working with the Chief Procurement Officer (CPO) and the Senior Project Manager (SPM) on soliciting bids for a series of HIPS and NIPS products for a major...
RFIRFQprocurement processvendor evaluation - Question #81Enterprise Security
To prevent a third party from identifying a specific user as having previously accessed a service provider through an SSO operation, SAML uses which of the following?
SAMLSSOtransient identifiersidentity federation - Question #82Enterprise Security
SAML entities can operate in a variety of different roles. Valid SAML roles include which of the following?
SAMLidentity providerservice providerfederation roles - Question #83Integration of Computing, Communications and Business Disciplines
A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but publ...
vendor risk managementsource code escrowcontract managementthird-party risk - Question #84Enterprise Security
A company decides to purchase COTS software. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?
COTS softwaresupply chain riskthird-party software - Question #85Enterprise Security
Which of the following is a security concern with deploying COTS products within the network?
COTS softwaresource code accesssecurity assessmentvendor risk - Question #86Technical Integration of Enterprise Components
The database team has suggested deploying a SOA based system across the enterprise. The Chief Information Officer (CIO) has decided to consult the security manager about the risk i...
SOAweb servicesdistributed architecturelegacy system exposure - Question #87Enterprise Security
The security team for Company XYZ has determined that someone from outside the organization has obtained sensitive information about the internal organization by querying the exter...
split DNSDNS securityinformation disclosurenetwork architecture - Question #88Enterprise Security
Unit testing for security functionality and resiliency to attack, as well as developing secure code and exploit mitigation, occur in which of the following phases of the Secure Sof...
SDLCsecure software implementationunit testingexploit mitigation - Question #89Enterprise Security
Which of the following are security components provided by an application security library or framework? (Select THREE).
application securityinput validationsecure loggingencryption - Question #90Enterprise Security
Which of the following potential vulnerabilities exists in the following code snippet? var myEmail = document.getElementById("formInputEmail").value; if (xmlhttp.readyState==4 && x...
DOM-based XSSJavaScriptAJAXweb application vulnerabilities - Question #91Enterprise Security
The Chief Information Security Officer (CISO) has just returned from attending a security conference and now wants to implement a Security Operations Center (SOC) to improve and co...
SOCSIEMintrusion detectionsecurity monitoring - Question #92Technical Integration of Enterprise Components
The IT Manager has mandated that an extensible markup language be implemented which can be used to exchange provisioning requests and responses for account creation. Which of the f...
SPMLXML provisioningidentity managementaccount lifecycle - Question #93Enterprise Security
A company is planning to deploy an in-house Security Operations Center (SOC). One of the new requirements is to deploy a NIPS solution into the Internet facing environment. The SOC...
NIPS placementnetwork architectureDMZinternet-facing security - Question #94Enterprise Security
A company recently experienced a malware outbreak. It was caused by a vendor using an approved non-company device on the company's corporate network that impacted manufacturing lin...
SCADA securityICSnetwork segmentationACL - Question #95Research and Analysis
Capital Reconnaissance, LLC is building a brand new research and testing location, and the physical security manager wants to deploy IP-based access control and video surveillance....
network baselinephysical security systemsthreat detectionanomaly detection - Question #96Technical Integration of Enterprise Components
A company has recently implemented a video conference solution that uses the H.323 protocol. The security engineer is asked to make recommendations on how to secure video conferenc...
H.323H.235video conferencing securityprotocol encryption - Question #97Enterprise Security
A healthcare company recently purchased the building next door located on the same campus. The building previously did not have any IT infrastructure. The building manager has sele...
physical securityserver room placementfacility securityenvironmental controls - Question #98Enterprise Security
A network security engineer would like to allow authorized groups to access network devices with a shell restricted to only show information while still authenticating the administ...
RADIUSTACACS+AAAnetwork device access control - Question #99Enterprise Security
An administrator is unable to connect to a server via VNC. Upon investigating the host firewall configuration, the administrator sees the following lines: - A INPUT -m state --stat...
iptablesfirewall rulesVNCport access control - Question #100Integration of Computing, Communications and Business Disciplines
Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals: - Prevent data breaches from lo...
data loss preventione-discoveryPII protectionrisk reduction strategy