CAS-001 Practice Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 6 of 11.
- Question #256
A storage administrator would like to make storage available to some hosts and unavailable to other hosts. Which of the following would be used?
- Question #257
Which of the following is a security advantage of single sign-on? (Select TWO).
- Question #258
After a system update causes significant downtime, the Chief Information Security Officer (CISO) asks the IT manager who was responsible for the update. The IT manager responds tha...
- Question #259
Company A is purchasing Company B, and will import all of Company B's users into its authentication system. Company A uses 802.1x with a RADIUS server, while Company B uses a capti...
- Question #260
A company has a legacy virtual cluster which was added to the datacenter after a small company was acquired. All VMs on the cluster use the same virtual network interface to connec...
- Question #261
A user reports that the workstation's mouse pointer is moving and files are opening automatically. Which of the following should the user perform?
- Question #262
The IT department of a large telecommunications company has developed and finalized a set of security solutions and policies which have been approved by upper management for deploy...
- Question #263
Employees have recently requested remote access to corporate email and shared drives. Remote access has never been offered; however, the need to improve productivity and rapidly re...
- Question #264
A manufacturing company is having issues with unauthorized access and modification of the controls operating the production equipment. A communication requirement is to allow the f...
- Question #265
A small bank is introducing online banking to its customers through its new secured website. The firewall has three interfaces: one for the Internet connection, another for the DMZ...
- Question #266
The Chief Information Officer (CIO) comes to the security manager and asks what can be done to reduce the potential of sensitive data being emailed out of the company. Which of the...
- Question #267
Virtual hosts with different security requirements should be:
- Question #268
Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:
- Question #269
When Company A and Company B merged, the network security administrator for Company A was tasked with joining the two networks. Which of the following should be done FIRST?
- Question #270
A legacy system is not scheduled to be decommissioned for two years and requires the use of the standard Telnet protocol. Which of the following should be used to mitigate the secu...
- Question #271
An ISP is peering with a new provider and wishes to disclose which autonomous system numbers should be allowed through BGP for network transport. Which of the following should cont...
- Question #272
A wholesaler has decided to increase revenue streams by selling direct to the public through an on- line system. Initially this will be run as a short term trial and if profitable,...
- Question #273
Unit testing for security functionality and resiliency to attack, as well as developing secure code and exploit mitigation, occur in which of the following phases of the Secure Sof...
- Question #274
Which of the following are security components provided by an application security library or framework? (Select THREE).
- Question #275
Which of the following are examples of privilege escalation? Each correct answer represents a complete solution. Choose two.
- Question #276
Which of the following is used to provide for the systematic review, retention and destruction of documents received or created in the course of business?
- Question #277
Which of the following statements are true about OCSP and CRL? Each correct answer represents a complete solution. Choose all that apply.
- Question #278
Cloud computing is significantly impacting the definition of network perimeters. Which of the following is NOT a network perimeter issue with cloud computing?
- Question #279
Which of the following types of Incident Response Teams (IRT) is responsible for a logical or physical segment of the infrastructure, usually of a large organization or one that is...
- Question #280
Denise works as a Security Administrator for a community college. She is assessing the various risks to her network. Which of the following is not a category of risk assessment?
- Question #281
A Chief Information Security Officer (CISO) of a major consulting firm has significantly increased the company's security posture; however, the company is still plagued by data bre...
- Question #282
The security administrator is responsible for the confidentiality of all corporate data. The company's servers are located in a datacenter run by a different vendor. The vendor dat...
- Question #283
Which of the following should be used to identify overflow vulnerabilities?
- Question #284
When attending the latest security conference, an information security administrator noticed only a few people carrying a laptop around. Most other attendees only carried their sma...
- Question #285
A network administrator notices a security intrusion on the web server. Which of the following is noticed by file?
- Question #286
The Chief Technology Officer (CTO) has decided that servers in the company datacenter should be virtualized to conserve physical space. The risk assurance officer is concerned that...
- Question #287
Due to cost and implementation time pressures, a security architect has allowed a NAS to be used instead of a SAN for a non-critical, low volume database. Which of the following wo...
- Question #288
An IT administrator wants to restrict DNS zone transfers between two geographically dispersed, external company DNS name servers, and has decided to use TSIG. Which of the followin...
- Question #289
As part of the ongoing information security plan in a large software development company, the Chief Information officer (CIO) has decided to review and update the company's privacy...
- Question #290
Which of the following is the BEST place to contractually document security priorities, responsibilities, guarantees, and warranties when dealing with outsourcing providers?
- Question #291
Staff from the sales department have administrator rights to their corporate standard operating environment, and often connect their work laptop to customer networks when onsite du...
- Question #292
The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's miss...
- Question #293
An organization determined that each of its remote sales representatives must use a smartphone for email access. The organization provides the same centrally manageable model to ea...
- Question #294
An organization did not know its internal customer and financial databases were compromised until the attacker published sensitive portions of the database on several popular attac...
- Question #295
An administrator has a system hardening policy to only allow network access to certain services, to always use similar hardware, and to protect from unauthorized application config...
- Question #296
About twice a year a switch fails in a company's network center. Under the maintenance contract, the switch would be replaced in two hours losing the business $1,000 per hour. The...
- Question #297
An administrator receives reports that the network is running slow for users connected to a certain switch. Viewing the network traffic, the administrator reviews the following: 18...
- Question #298
An intrusion detection system logged an attack attempt from a remote IP address. One week later, the attacker successfully compromised the network. Which of the following MOST like...
- Question #299
A company receives a subpoena for email that is four years old. Which of the following should the company consult to determine if it can provide the email in question?
- Question #300
A new company requirement mandates the implementation of multi-factor authentication to access network resources. The security administrator was asked to research and implement the...
- Question #301
The internal audit department is investigating a possible breach of security. One of the auditors is sent to interview the following employees: - Employee A. Works in the accounts...
- Question #302
A company's security policy states that its own internally developed proprietary Internet facing software must be resistant to web application attacks. Which of the following metho...
- Question #303
An organization is preparing to upgrade its firewall and NIPS infrastructure and has narrowed the vendor choices down to two platforms. The integrator chosen to assist the organiza...
- Question #304
An administrator has four virtual guests on a host server. Two of the servers are corporate SQL servers, one is a corporate mail server, and one is a testing web server for a small...
- Question #305
An administrator receives a notification from legal that an investigation is being performed on members of the finance department. As a precaution, legal has advised a legal hold o...