CAS-001 Exam Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 6 of 11.
- Question #256Technical Integration of Enterprise Components
A storage administrator would like to make storage available to some hosts and unavailable to other hosts. Which of the following would be used?
LUN maskingSAN access controlstorage managementhost isolation - Question #257Enterprise Security
Which of the following is a security advantage of single sign-on? (Select TWO).
single sign-onauthenticationidentity managementaccess removal - Question #258Integration of Computing, Communications and Business Disciplines
After a system update causes significant downtime, the Chief Information Security Officer (CISO) asks the IT manager who was responsible for the update. The IT manager responds tha...
change managementuser auditingaccountabilityIT governance - Question #259Technical Integration of Enterprise Components
Company A is purchasing Company B, and will import all of Company B's users into its authentication system. Company A uses 802.1x with a RADIUS server, while Company B uses a capti...
802.1xRADIUSLDAPauthentication integration - Question #260Technical Integration of Enterprise Components
A company has a legacy virtual cluster which was added to the datacenter after a small company was acquired. All VMs on the cluster use the same virtual network interface to connec...
VM network isolationvirtual switchingtraffic visibilitydata confidentiality - Question #261Enterprise Security
A user reports that the workstation's mouse pointer is moving and files are opening automatically. Which of the following should the user perform?
incident responseremote access attacksecurity awarenessescalation - Question #262Integration of Computing, Communications and Business Disciplines
The IT department of a large telecommunications company has developed and finalized a set of security solutions and policies which have been approved by upper management for deploy...
security policystakeholder managementrequirements gatheringgovernance - Question #263Enterprise Security
Employees have recently requested remote access to corporate email and shared drives. Remote access has never been offered; however, the need to improve productivity and rapidly re...
remote accesszero trustsecurity policynetwork security - Question #264Technical Integration of Enterprise Components
A manufacturing company is having issues with unauthorized access and modification of the controls operating the production equipment. A communication requirement is to allow the f...
AAASCADAindustrial control systemsaccess control - Question #265Enterprise Security
A small bank is introducing online banking to its customers through its new secured website. The firewall has three interfaces: one for the Internet connection, another for the DMZ...
HIPSdefense in depthDMZweb application security - Question #266Enterprise Security
The Chief Information Officer (CIO) comes to the security manager and asks what can be done to reduce the potential of sensitive data being emailed out of the company. Which of the...
DLPdata exfiltrationcontent filteringemail security - Question #267Technical Integration of Enterprise Components
Virtual hosts with different security requirements should be:
virtualizationsecurity isolationphysical separationmulti-tenancy - Question #268Enterprise Security
Corporate policy states that the systems administrator should not be present during system audits. The security policy that states this is:
separation of dutiessecurity policyaudit controls - Question #269Research and Analysis
When Company A and Company B merged, the network security administrator for Company A was tasked with joining the two networks. Which of the following should be done FIRST?
vulnerability assessmentnetwork mergerdue diligencepenetration testing - Question #270Technical Integration of Enterprise Components
A legacy system is not scheduled to be decommissioned for two years and requires the use of the standard Telnet protocol. Which of the following should be used to mitigate the secu...
VLAN segmentationlegacy systemsTelnetnetwork isolation - Question #271Technical Integration of Enterprise Components
An ISP is peering with a new provider and wishes to disclose which autonomous system numbers should be allowed through BGP for network transport. Which of the following should cont...
BGPinterconnection security agreementnetwork peeringautonomous systems - Question #272Integration of Computing, Communications and Business Disciplines
A wholesaler has decided to increase revenue streams by selling direct to the public through an on- line system. Initially this will be run as a short term trial and if profitable,...
risk transferPCI DSSoutsourcingrisk management - Question #275Enterprise Security
Which of the following are examples of privilege escalation? Each correct answer represents a complete solution. Choose two.
privilege escalationaccess controlauthentication bypasslateral movement - Question #276Integration of Computing, Communications and Business Disciplines
Which of the following is used to provide for the systematic review, retention and destruction of documents received or created in the course of business?
document retention policyrecords managementcompliancedata lifecycle - Question #277Enterprise Security
Which of the following statements are true about OCSP and CRL? Each correct answer represents a complete solution. Choose all that apply.
OCSPCRLPKIcertificate revocation - Question #278Technical Integration of Enterprise Components
Cloud computing is significantly impacting the definition of network perimeters. Which of the following is NOT a network perimeter issue with cloud computing?
cloud securitynetwork perimeterdata residencyregulatory compliance - Question #279Enterprise Security
Which of the following types of Incident Response Teams (IRT) is responsible for a logical or physical segment of the infrastructure, usually of a large organization or one that is...
incident responseIRT typesdistributed IRTorganizational structure - Question #280Research and Analysis
Denise works as a Security Administrator for a community college. She is assessing the various risks to her network. Which of the following is not a category of risk assessment?
risk assessmentrisk managementvulnerability assessmentrisk categories - Question #281Enterprise Security
A Chief Information Security Officer (CISO) of a major consulting firm has significantly increased the company's security posture; however, the company is still plagued by data bre...
full disk encryptiondata breachasset managementendpoint security - Question #282Technical Integration of Enterprise Components
The security administrator is responsible for the confidentiality of all corporate data. The company's servers are located in a datacenter run by a different vendor. The vendor dat...
port securityIPSecphysical accessnetwork hardening - Question #283Research and Analysis
Which of the following should be used to identify overflow vulnerabilities?
fuzzingbuffer overflowvulnerability testingapplication security - Question #285Enterprise Security
A network administrator notices a security intrusion on the web server. Which of the following is noticed by file?
XSSweb server securityweb attacksintrusion detection - Question #286Technical Integration of Enterprise Components
The Chief Technology Officer (CTO) has decided that servers in the company datacenter should be virtualized to conserve physical space. The risk assurance officer is concerned that...
virtualization securityhypervisorguest OS isolationVM escape - Question #287Technical Integration of Enterprise Components
Due to cost and implementation time pressures, a security architect has allowed a NAS to be used instead of a SAN for a non-critical, low volume database. Which of the following wo...
NASSANstorage latencybroadcast storms - Question #288Technical Integration of Enterprise Components
An IT administrator wants to restrict DNS zone transfers between two geographically dispersed, external company DNS name servers, and has decided to use TSIG. Which of the followin...
TSIGDNS zone transferkey exchangetime synchronization - Question #289Integration of Computing, Communications and Business Disciplines
As part of the ongoing information security plan in a large software development company, the Chief Information officer (CIO) has decided to review and update the company's privacy...
security awarenesstraining customizationprivacy policyorganizational roles - Question #290Integration of Computing, Communications and Business Disciplines
Which of the following is the BEST place to contractually document security priorities, responsibilities, guarantees, and warranties when dealing with outsourcing providers?
SLAoutsourcingthird-party riskcontractual security - Question #291Enterprise Security
Staff from the sales department have administrator rights to their corporate standard operating environment, and often connect their work laptop to customer networks when onsite du...
network access controlendpoint postureremote accesscorporate LAN - Question #292Integration of Computing, Communications and Business Disciplines
The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's miss...
SSDLCsoftware development lifecyclePCI-DSSHIPAA compliance - Question #293Enterprise Security
An organization determined that each of its remote sales representatives must use a smartphone for email access. The organization provides the same centrally manageable model to ea...
mobile device managementremote wipePIN policydata confidentiality - Question #294Research and Analysis
An organization did not know its internal customer and financial databases were compromised until the attacker published sensitive portions of the database on several popular attac...
loggingforensicsincident responsesecurity monitoring - Question #295Technical Integration of Enterprise Components
An administrator has a system hardening policy to only allow network access to certain services, to always use similar hardware, and to protect from unauthorized application config...
system hardeninghost firewallvirtualizationapplication control - Question #296Integration of Computing, Communications and Business Disciplines
About twice a year a switch fails in a company's network center. Under the maintenance contract, the switch would be replaced in two hours losing the business $1,000 per hour. The...
risk analysiscost-benefit analysisbusiness continuitymaintenance contracts - Question #297Research and Analysis
An administrator receives reports that the network is running slow for users connected to a certain switch. Viewing the network traffic, the administrator reviews the following: 18...
network traffic analysisDNS queriesnetwork zoningpacket capture - Question #298Enterprise Security
An intrusion detection system logged an attack attempt from a remote IP address. One week later, the attacker successfully compromised the network. Which of the following MOST like...
IDS log reviewfalse positivesintrusion detectionsecurity monitoring - Question #299Integration of Computing, Communications and Business Disciplines
A company receives a subpoena for email that is four years old. Which of the following should the company consult to determine if it can provide the email in question?
data retentione-discoverylegal complianceemail archiving - Question #300Enterprise Security
A new company requirement mandates the implementation of multi-factor authentication to access network resources. The security administrator was asked to research and implement the...
multi-factor authenticationPKIcertificate-based authpublic key infrastructure - Question #301Enterprise Security
The internal audit department is investigating a possible breach of security. One of the auditors is sent to interview the following employees: - Employee A. Works in the accounts...
separation of dutiesaccess controlleast privilegefinance security - Question #302Enterprise Security
A company's security policy states that its own internally developed proprietary Internet facing software must be resistant to web application attacks. Which of the following metho...
secure codingweb application securitySQL injectioninput validation - Question #303Research and Analysis
An organization is preparing to upgrade its firewall and NIPS infrastructure and has narrowed the vendor choices down to two platforms. The integrator chosen to assist the organiza...
firewall evaluationNIPSvendor assessmentsecurity testing - Question #304Technical Integration of Enterprise Components
An administrator has four virtual guests on a host server. Two of the servers are corporate SQL servers, one is a corporate mail server, and one is a testing web server for a small...
virtualizationout-of-band managementnetwork segmentationmanagement NIC - Question #305Integration of Computing, Communications and Business Disciplines
An administrator receives a notification from legal that an investigation is being performed on members of the finance department. As a precaution, legal has advised a legal hold o...
legal holddata retentione-discoverydata storage policy - Question #306Enterprise Security
Which of the following BEST explains SAML?
SAMLSSOfederated identityXML - Question #307Integration of Computing, Communications and Business Disciplines
The organization has an IT driver on cloud computing to improve delivery times for IT solution provisioning. Separate to this initiative, a business case has been approved for repl...
cloud computingPCI DSSregulatory compliancerisk management - Question #308Integration of Computing, Communications and Business Disciplines
The Universal Research Association has just been acquired by the Association of Medical Business Researchers. The new conglomerate has funds to upgrade or replace hardware as part...
mergers and acquisitionsIT integrationregulatory conflictindustry standards