CAS-001 Practice Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 4 of 11.
- Question #156
A security administrator wants to verify and improve the security of a business process which is tied to proven company workflow. The security administrator was able to improve sec...
- Question #157
A company receives an e-discovery request for the Chief Information Officer's (CIO's) email data. The storage administrator reports that the data retention policy relevant to their...
- Question #158
The VoIP administrator starts receiving reports that users are having problems placing phone calls. The VoIP administrator cannot determine the issue, and asks the security adminis...
- Question #159
The Chief Information Security Officer (CISO) of a small bank wants to embed a monthly testing regiment into the security management plan specifically for the development area. The...
- Question #160
A large corporation which is heavily reliant on IT platforms and systems is in financial difficulty and needs to drastically reduce costs in the short term to survive. The Chief Fi...
- Question #161
A small customer focused bank with implemented least privilege principles, is concerned about the possibility of branch staff unintentionally aiding fraud in their day to day inter...
- Question #162
A hosting company provides inexpensive guest virtual machines to low-margin customers. Customers manage their own guest virtual machines. Some customers want basic guarantees of lo...
- Question #163
A financial company implements end-to-end encryption via SSL in the DMZ, and only IPSec in transport mode with AH enabled and ESP disabled throughout the internal network. The comp...
- Question #164
A developer is coding the crypto routine of an application that will be installed on a standard headless and diskless server connected to a NAS housed in the datacenter. The develo...
- Question #165
After three vendors submit their requested documentation, the CPO and the SPM can better understand what each vendor does and what solutions that they can provide. But now they wan...
- Question #166
The <nameID> element in SAML can be provided in which of the following predefined formats? (Select TWO).
- Question #167
A corporation has expanded for the first time by integrating several newly acquired businesses. Which of the following are the FIRST tasks that the security team should undertake?...
- Question #168
New zero-day attacks are announced on a regular basis against a broad range of technology systems. Which of the following best practices should a security manager do to manage the...
- Question #169
A WAF without customization will protect the infrastructure from which of the following attack combinations?
- Question #170
(CRM) and marketing / leads management to Company XYZ. Which of the following is the MOST important to be considered before going ahead with the service?
- Question #171
The Linux server at Company A hosts a graphical application widely used by the company designers. One designer regularly connects to the server from a Mac laptop in the designer's...
- Question #172
A data breach has occurred at Company A and as a result, the Chief Information Officer (CIO) has resigned. The CIO's laptop, cell phone and PC were all wiped of data per company po...
- Question #173
A security administrator at a Lab Company is required to implement a solution which will provide the highest level of confidentiality possible to all data on the lab network. The c...
- Question #174
A data processing server uses a Linux based file system to remotely mount physical disks on a shared SAN. The server administrator reports problems related to processing of files w...
- Question #175
databases, web portals, and cloud data sets. Each data store had a unique set of custom developed authentication mechanisms and schemas. Which of the following approaches to combin...
- Question #176
A security researcher is about to evaluate a new secure VoIP routing appliance. The appliance manufacturer claims the new device is hardened against all known attacks and several u...
- Question #177
Customer Need: "We need the system to produce a series of numbers with no discernible mathematical progression for use by our Java based, PKI-enabled, customer facing website." Whi...
- Question #178
A security engineer is implementing a new solution designed to process e-business transactions and record them in a corporate audit database. The project has multiple technical sta...
- Question #179
A large financial company has a team of security-focused architects and designers that contribute into broader IT architecture and design solutions. Concerns have been raised due t...
- Question #180
A University uses a card transaction system that allows students to purchase goods using their student ID . Students can put money on their ID at terminals throughout the campus. T...
- Question #181
Which of the following attacks does Unicast Reverse Path Forwarding prevent?
- Question #182
Which of the following authentication types is used primarily to authenticate users through the use of tickets?
- Question #183
A security consultant is evaluating forms which will be used on a company website. Which of the following techniques or terms is MOST effective at preventing malicious individuals...
- Question #184
A security audit has uncovered that some of the encryption keys used to secure the company B2B financial transactions with its partners may be too weak. The security administrator...
- Question #185
A company provides on-demand virtual computing for a sensitive project. The company implements a fully virtualized datacenter and terminal server access with two-factor authenticat...
- Question #186
Company XYZ provides residential television cable service across a large region. The company's board of directors is in the process of approving a deal with the following three com...
- Question #187
The security administrator at a bank is receiving numerous reports that customers are unable to login to the bank website. Upon further investigation, the security administrator di...
- Question #188
A security administrator has finished building a Linux server which will host multiple virtual machines through hypervisor technology. Management of the Linux server, including mon...
- Question #189
A breach at a government agency resulted in the public release of top secret information. The Chief Information Security Officer has tasked a group of security professionals to dep...
- Question #190
financial system. The audit report indicates that the accounts receivable department has not followed proper record disposal procedures during a COOP/BCP tabletop exercise involvin...
- Question #191
The security administrator is receiving numerous alerts from the internal IDS of a possible Conficker infection spreading through the network via the Windows file sharing services....
- Question #192
A company currently does not use any type of authentication or authorization service for remote access. The new security policy states that all remote access must be locked down to...
- Question #193
Which of the following displays an example of a buffer overflow attack?
- Question #194
Which of the following displays an example of a XSS attack?
- Question #195
Several critical servers are unresponsive after an update was installed. Other computers that have not yet received the same update are operational, but are vulnerable to certain b...
- Question #196
A business is currently in the process of upgrading its network infrastructure to accommodate a personnel growth of over fifty percent within the next six months. All preliminary p...
- Question #197
Which of the following must be taken into consideration for e-discovery purposes when a legal case is first presented to a company?
- Question #198
A company has purchased a new system, but security personnel are spending a great deal of time on system maintenance. A new third party vendor has been selected to maintain and man...
- Question #199
The security administrator of a small private firm is researching and putting together a proposal to purchase an IPS to replace an existing IDS. A specific brand and model has been...
- Question #200
A security administrator of a large private firm is researching and putting together a proposal to purchase an IPS. The specific IPS type has not been selected, and the security ad...
- Question #201
Wireless users are reporting issues with the company's video conferencing and VoIP systems. The security administrator notices DOS attacks on the network that are affecting the com...
- Question #202
A company has decided to use the SDLC for the creation and production of a new information system. The security administrator is training all users on how to protect company inform...
- Question #203
A company contracts with a third party to develop a new web application to process credit cards. Which of the following assessments will give the company the GREATEST level of assu...
- Question #204
A system designer needs to factor in CIA requirements for a new SAN. Which of the CIA requirements is BEST met by multipathing?
- Question #205
An internal employee has sold a copy of the production customer database that was being used for upgrade testing to outside parties via HTTP file upload. The Chief Information Offi...