CAS-001 Practice Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 2 of 11.
- Question #51
A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the co...
- Question #52
Company XYZ has invested an increasing amount in security due to the changing threat landscape. The company is going through a cost cutting exercise and the Chief Financial Officer...
- Question #53
There has been a recent security breach which has led to the release of sensitive customer information. As part of improving security and reducing the disclosure of customer data,...
- Question #54
A new malware spreads over UDP Port 8320 and several network hosts have been infected. A new security administrator has determined a possible cause, and the infected machines have...
- Question #55
A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situa...
- Question #56
A small company has recently placed a newly installed DNS server on the DMZ and wants to secure it by allowing Internet hosts to query the DNS server. Since the company deploys an...
- Question #57
An administrator would like to connect a server to a SAN. Which of the following processes would BEST allow for availability and access control?
- Question #58
A company data center provides Internet based access to email and web services. The firewall is separated into four zones: - RED ZONE is an Internet zone - ORANGE ZONE a Web DMZ -...
- Question #59
An administrator implements a new PHP application into an existing website and discovers the newly added PHP pages do not work. The rest of the site also uses PHP and is functionin...
- Question #60
Company GHI consolidated their network distribution so twelve network VLANs would be available over dual fiber links to a modular L2 switch in each of the company's six IDFs. The I...
- Question #61
After a recent outbreak of malware attacks, the Chief Information Officer (CIO) tasks the new security manager with determining how to keep these attacks from reoccurring. The comp...
- Question #62
The Chief Information Officer (CIO) of Company XYZ has returned from a large IT conference where one of the topics was defending against zero day attacks ?specifically deploying th...
- Question #63
When planning a complex system architecture, it is important to build in mechanisms to secure log information, facilitate audit log reduction, and event correlation. Besides synchr...
- Question #64
Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?
- Question #65
A corporation relies on a server running a trusted operating system to broker data transactions between different security zones on their network. Each zone is a separate domain an...
- Question #66
A system architect has the following constraints from the customer: - Confidentiality, Integrity, and Availability (CIA) are all of equal importance. - Average availability must be...
- Question #67
The security administrator reports that the physical security of the Ethernet network has been breached, but the fibre channel storage network was not breached. Why might this stil...
- Question #68
As part of a new wireless implementation, the Chief Information Officer's (CIO's) main objective is to immediately deploy a system that supports the 802.11r standard, which will he...
- Question #69
A firm's Chief Executive Officer (CEO) is concerned that its IT staff lacks the knowledge to identify complex vulnerabilities that may exist in the payment system being internally...
- Question #70
The security manager is in the process of writing a business case to replace a legacy secure web gateway so as to meet an availability requirement of 99.9% service availability. Ac...
- Question #71
What of the following vulnerabilities is present in the below source code file named `AuthenticatedArea.php'? <html><head><title>AuthenticatedArea</title></head> <? include ("/inc/...
- Question #72
There have been some failures of the company's customer-facing website. A security engineer has analyzed the root cause to be the WAF. System logs show that the WAF has been down f...
- Question #73
To support a software security initiative business case, a project manager needs to provide a cost benefit analysis. The project manager has asked the security consultant to perfor...
- Question #74
During user acceptance testing, the security administrator believes to have discovered an issue in the login prompt of the company's financial system. While entering the username a...
- Question #75
The network administrator has been tracking the cause of network performance problems and decides to take a look at the internal and external router stats. Which of the following s...
- Question #76
A security administrator wants to perform an audit of the company password file to ensure users are not using personal information such as addresses and birthdays as part of their...
- Question #77
The security administrator at `company.com' is reviewing the network logs and notices a new UDP port pattern where the amount of UDP port 123 packets has increased by 20% above the...
- Question #78
A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a...
- Question #79
A Chief Information Security Officer (CISO) has been trying to eliminate some IT security risks for several months. These risks are not high profile but still exist. Furthermore, m...
- Question #80
The firm's CISO has been working with the Chief Procurement Officer (CPO) and the Senior Project Manager (SPM) on soliciting bids for a series of HIPS and NIPS products for a major...
- Question #81
To prevent a third party from identifying a specific user as having previously accessed a service provider through an SSO operation, SAML uses which of the following?
- Question #82
SAML entities can operate in a variety of different roles. Valid SAML roles include which of the following?
- Question #83
A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but publ...
- Question #84
A company decides to purchase COTS software. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?
- Question #85
Which of the following is a security concern with deploying COTS products within the network?
- Question #86
The database team has suggested deploying a SOA based system across the enterprise. The Chief Information Officer (CIO) has decided to consult the security manager about the risk i...
- Question #87
The security team for Company XYZ has determined that someone from outside the organization has obtained sensitive information about the internal organization by querying the exter...
- Question #88
Unit testing for security functionality and resiliency to attack, as well as developing secure code and exploit mitigation, occur in which of the following phases of the Secure Sof...
- Question #89
Which of the following are security components provided by an application security library or framework? (Select THREE).
- Question #90
Which of the following potential vulnerabilities exists in the following code snippet? var myEmail = document.getElementById("formInputEmail").value; if (xmlhttp.readyState==4 && x...
- Question #91
The Chief Information Security Officer (CISO) has just returned from attending a security conference and now wants to implement a Security Operations Center (SOC) to improve and co...
- Question #92
The IT Manager has mandated that an extensible markup language be implemented which can be used to exchange provisioning requests and responses for account creation. Which of the f...
- Question #93
A company is planning to deploy an in-house Security Operations Center (SOC). One of the new requirements is to deploy a NIPS solution into the Internet facing environment. The SOC...
- Question #94
A company recently experienced a malware outbreak. It was caused by a vendor using an approved non-company device on the company's corporate network that impacted manufacturing lin...
- Question #95
Capital Reconnaissance, LLC is building a brand new research and testing location, and the physical security manager wants to deploy IP-based access control and video surveillance....
- Question #96
A company has recently implemented a video conference solution that uses the H.323 protocol. The security engineer is asked to make recommendations on how to secure video conferenc...
- Question #97
A healthcare company recently purchased the building next door located on the same campus. The building previously did not have any IT infrastructure. The building manager has sele...
- Question #98
A network security engineer would like to allow authorized groups to access network devices with a shell restricted to only show information while still authenticating the administ...
- Question #99
An administrator is unable to connect to a server via VNC. Upon investigating the host firewall configuration, the administrator sees the following lines: - A INPUT -m state --stat...
- Question #100
Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals: - Prevent data breaches from lo...