CAS-001 Exam Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 7 of 11.
- Question #309Technical Integration of Enterprise Components
A large enterprise introduced a next generation firewall appliance into the Internet facing DMZ. All Internet traffic passes through this appliance. Four hours after implementation...
firewall deploymentperformance testingDMZimplementation lifecycle - Question #310Integration of Computing, Communications and Business Disciplines
A company has implemented data retention policies and storage quotas in response to their legal department's requests and the SAN administrator's recommendation. The retention poli...
e-discoverylegal holddata retention conflictcompliance - Question #311Technical Integration of Enterprise Components
A security administrator is tasked with securing a company's headquarters and branch offices move to unified communications. The Chief Information Officer (CIO) wants to integrate...
unified communicationsVoIP securitySRTPpresence management - Question #312Enterprise Security
Ann, a Physical Security Manager, is ready to replace all 50 analog surveillance cameras with IP cameras with built-in web management. Ann has several security guard desks on diffe...
IP camerasauthentication proxynetwork segmentationcompensating controls - Question #313Technical Integration of Enterprise Components
A general insurance company wants to set up a new online business. The requirements are that the solution needs to be: - Extendable for new products to be developed and added - Ext...
WS-SecurityXACMLweb services architectureSSL/TLS - Question #314Enterprise Security
A retail bank has had a number of issues in regards to the integrity of sensitive information across all of its customer databases. This has resulted in the bank's share price decr...
SIEMsecurity monitoringaudit loggingincident response - Question #315Research and Analysis
Company XYZ has employed a consultant to perform a controls assessment of the HR system, backend business operations, and the SCADA system used in the factory. Which of the followi...
risk treatmentrisk managementavoid transfer mitigate acceptcontrols assessment - Question #316Enterprise Security
Company XYZ has had repeated vulnerability exploits of a critical nature released to the company's flagship product. The product is used by a number of large customers. At the Chie...
vulnerability managementsecure SDLCproduct securitystrategic remediation - Question #317Technical Integration of Enterprise Components
A system administrator has installed a new Internet facing secure web application that consists of a Linux web server and Windows SQL server into a new corporate site. The administ...
DMZnetwork segmentationfirewall zonesweb application architecture - Question #318Integration of Computing, Communications and Business Disciplines
The lead systems architect on a software development project developed a design which is optimized for a distributed computing environment. The security architect assigned to the p...
security governancerisk communicationcloud securitystakeholder management - Question #319Enterprise Security
Company XYZ plans to donate 1,000 used computers to a local school. The company has a large research and development section and some of the computers were previously used to store...
data sanitizationmedia disposaldata remnantsdata handling policy - Question #320Enterprise Security
Continuous monitoring is a popular risk reduction technique in many large organizations with formal certification processes for IT projects. In order to implement continuous monito...
continuous monitoringlog managementsecurity alertingrisk reduction - Question #321Integration of Computing, Communications and Business Disciplines
The Chief Information Security Officer (CISO) regularly receives reports of a single department repeatedly violating the corporate security policy. The head of the department in qu...
MOUsecurity policygovernancerisk acceptance - Question #322Research and Analysis
A security administrator at Company XYZ is trying to develop a body of knowledge to enable heuristic and behavior based security event monitoring of activities on a geographically...
network baselineheuristic monitoringnetwork instrumentationbehavioral analysis - Question #323Technical Integration of Enterprise Components
A new IDS device is generating a very large number of irrelevant events. Which of the following would BEST remedy this problem?
IDS tuningfalse positivesintrusion detectionanomaly detection - Question #324Enterprise Security
The Chief Information Security Officer (CISO) at a software development company is concerned about the lack of introspection during a testing cycle of the company's flagship produc...
white box testingcode coveragesoftware security testingsecurity QA - Question #325Enterprise Security
A security code reviewer has been engaged to manually review a legacy application. A number of systemic issues have been uncovered relating to buffer overflows and format string vu...
managed codebuffer overflowsecure programming languagesformat string vulnerability - Question #326Technical Integration of Enterprise Components
A bank now has a major initiative to virtualize as many servers as possible, due to power and rack space capacity at both data centers. The bank has prioritized by virtualizing old...
server virtualizationnetwork segmentationVM isolationdata center architecture - Question #327Technical Integration of Enterprise Components
After being informed that the company DNS is unresponsive, the system administrator issues the following command from a Linux workstation: - SSH-p 2020 -l user dnsserver.company.co...
Linux administrationSSHprivilege escalationDNS service management - Question #328Technical Integration of Enterprise Components
Which of the following is an example of single sign-on?
single sign-onweb access controlHTTP header attributesfederated authentication - Question #330Enterprise Security
In developing a new computing lifecycle process for a large corporation, the security team is developing the process for decommissioning computing equipment. In order to reduce the...
data sanitizationdrive destructiondecommissioningdata leakage prevention - Question #331Integration of Computing, Communications and Business Disciplines
A Security Manager is part of a team selecting web conferencing systems for internal use. The system will only be used for internal employee collaboration. Which of the following a...
web conferencing securitydata storage securityuser authenticationsystem availability - Question #332Technical Integration of Enterprise Components
The security administrator has just installed an active\passive cluster of two firewalls for enterprise perimeter defense of the corporate network. Stateful firewall inspection is...
stateful firewallactive-passive clustersession synchronizationfirewall failover - Question #333Integration of Computing, Communications and Business Disciplines
activities have uncovered systemic security issues in the flagship product of Company average estimates indicating a cost of $1.6millon. Which of the following approaches should th...
risk avoidancerisk treatmentrisk managementproduct security risk - Question #334Enterprise Security
Which of the following are components defined within an Enterprise Security Architecture Framework? (Select THREE).
enterprise security architecturereference modelsbusiness capabilitiessecurity framework - Question #335Technical Integration of Enterprise Components
An audit at a popular on-line shopping site reveals that a flaw in the website allows customers to purchase goods at a discounted rate. To improve security the Chief Information Se...
web application testinginput validationfuzzingHTTP interception - Question #336Integration of Computing, Communications and Business Disciplines
An external auditor has found that IT security policies in the organization are not maintained and in some cases are nonexistent. As a result of the audit findings, the CISO has be...
policy lifecycle managementeGRCIT security governanceCISO - Question #337Technical Integration of Enterprise Components
In a SPML exchange, which of the following BEST describes the three primary roles?
SPMLprovisioning rolesidentity provisioningRequest Authority - Question #338Technical Integration of Enterprise Components
A trust relationship has been established between two organizations with web based services. One organization is acting as the Requesting Authority (RA) and the other acts as the P...
SAMLSPMLfederated identitytrust relationship - Question #339Technical Integration of Enterprise Components
A Security Administrator has some concerns about the confidentiality of data when using SOAP. Which of the following BEST describes the Security Administrator's concerns?
SOAP securityheader encryptionweb servicesintermediary attacks - Question #340Technical Integration of Enterprise Components
Which of the following protocols only facilitates access control?
XACMLaccess control protocolsauthorizationSAML vs XACML - Question #341Integration of Computing, Communications and Business Disciplines
upcoming merger and are both concerned with minimizing security exposures to each others network throughout the test. Which of the following is the FIRST thing both sides should do...
network mergerdata flow analysissecurity planningrisk management - Question #342Research and Analysis
Company management has indicated that instant messengers (IM) add to employee productivity. Management would like to implement an IM solution, but does not have a budget for the pr...
instant messaging securityproduct evaluationfeature matrixsecurity requirements - Question #343Technical Integration of Enterprise Components
An administrator attempts to install the package "named.9.3.6-12-x86_64.rpm" on a server. Even though the package was downloaded from the official repository, the server states the...
GPG keypackage verificationRPMpublic key infrastructure - Question #344Technical Integration of Enterprise Components
Two storage administrators are discussing which SAN configurations will offer the MOST confidentiality. Which of the following configurations would the administrators use? (Select...
SAN securityzoningLUN maskingstorage confidentiality - Question #345Enterprise Security
When generating a new key pair, a security application asks the user to move the mouse and type random characters on the keyboard. Which of the following BEST describes why this is...
key generationentropycryptographyrandomness - Question #346Enterprise Security
Company XYZ has experienced a breach and has requested an internal investigation be conducted by the IT Department. Which of the following represents the correct order of the inves...
digital forensicsincident investigationevidence handlingchain of custody - Question #347Integration of Computing, Communications and Business Disciplines
A medium-sized company has recently launched an online product catalog. It has decided to keep the credit card purchasing in-house as a secondary potential income stream has been i...
PCI DSScomplianceindustry standardsregulatory requirements - Question #348Enterprise Security
a different manufacturing ICS platform. Company XYZ has strict ICS security regulations while Which of the following approaches would the network security administrator for Company...
ICS securitySCADArisk assessmentnetwork integration - Question #349Research and Analysis
An Association is preparing to upgrade their firewalls at five locations around the United States. Each of the three vendor's RFP responses is in-line with the security and other r...
firewall evaluationvendor selectionlab testingRFP - Question #350Enterprise Security
At 10:35 a.m. a malicious user was able to obtain a valid authentication token which allowed read/write access to the backend database of a financial company. At 10:45 a.m. the sec...
authentication tokenrace conditionIDS alertsincident analysis - Question #351Integration of Computing, Communications and Business Disciplines
Company A is purchasing Company B. Company A uses a change management system for all IT processes while Company B does not have one in place. Company B's IT staff needs to purchase...
change managementmerger acquisitionIT governancethird-party products - Question #352Enterprise Security
The marketing department at Company A regularly sends out emails signed by the company's Chief Executive Officer (CEO) with announcements about the company. The CEO sends company a...
digital signaturesnon-repudiationPKIemail security - Question #353Technical Integration of Enterprise Components
A security administrator must implement a SCADA style network overlay to ensure secure remote management of all network management and infrastructure devices. Which of the followin...
SCADAout-of-band managementnetwork isolationremote management - Question #354Technical Integration of Enterprise Components
A helpdesk manager at a financial company has received multiple reports from employees and customers that their phone calls sound metallic on the voice system. The helpdesk has bee...
VoIPVLANnetwork qualityPBX - Question #355Enterprise Security
Which of the following provides the HIGHEST level of security for an integrated network providing services to authenticated corporate users?
security architecturemulti-factor authenticationVPNnetwork security - Question #356Integration of Computing, Communications and Business Disciplines
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which...
risk managementplan of actionvulnerability managementcontinuous monitoring - Question #357Research and Analysis
Company XYZ has transferred all of the corporate servers, including web servers, to a cloud hosting provider to reduce costs. All of the servers are running unpatched, outdated ver...
cloud securitypatch managementrisk assessmentserver hardening - Question #358Enterprise Security
You need to ensure that a session key derived from a set of long-term public and private keys will not be compromised if one of the private keys is compromised in the future?
perfect forward secrecycryptographysession keyskey compromise - Question #359Technical Integration of Enterprise Components
The Security Development Lifecycle (SDL) consists of various security practices that are grouped under seven phases. Which of the following security practices are included in the R...
SDLsecurity development lifecyclerequirements phasesecurity practices