CAS-001 Practice Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 8 of 11.
- Question #356
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which...
- Question #357
Company XYZ has transferred all of the corporate servers, including web servers, to a cloud hosting provider to reduce costs. All of the servers are running unpatched, outdated ver...
- Question #358
You need to ensure that a session key derived from a set of long-term public and private keys will not be compromised if one of the private keys is compromised in the future?
- Question #359
The Security Development Lifecycle (SDL) consists of various security practices that are grouped under seven phases. Which of the following security practices are included in the R...
- Question #360
Which of the following components of a VoIP network is frequently used to bridge video conferencing connections?
- Question #361
Which of the following is a declarative access control policy language implemented in XML and a processing model, describing how to interpret the policies?
- Question #362
You want to allow some users to access a particular program on the computers in the network. What will you do to accomplish this task?
- Question #363
Which of the following is the most secure authentication scheme and uses a public key cryptography and digital certificate to authenticate a user?
- Question #364
Which of the following security practices are included in the Implementation phase of the Security Development Lifecycle (SDL)? Each correct answer represents a complete solution....
- Question #365
In which of the following activities an organization identifies and prioritizes technical, organizational, procedural, administrative, and physical security weaknesses?
- Question #366
SDLC phases include a minimum set of security tasks that are required to effectively incorporate security in the system development process. Which of the following are the key secu...
- Question #367
Which of the following is an XML-based framework developed by OASIS and used to exchange user, resource and service provisioning information between cooperating organizations?
- Question #368
Which of the following terms is about communicating the user's need and ability to communicate, and the medium through which that communication may occur?
- Question #369
Which technology can be used to help ensure the efficient transport of VoIP traffic?
- Question #370
In which of the following attacks does an attacker intercept call-signaling SIP message traffic and masquerade as the calling party to the called party and vice-versa?
- Question #371
Which of the following protocols is used extensively in communication and entertainment systems that involve streaming media, such as telephony, video teleconference applications a...
- Question #372
Collaboration platform offers a set of software components and services that enable users to communicate, share information, and work together for achieving common business goals....
- Question #373
Which of the following stages are involved in the successful implementation of a collaboration platform? Each correct answer represents a part of the solution. Choose two.
- Question #374
You want the clients and servers in your organization to be able to communicate in a way that prevents eavesdropping and tampering of data on the Internet. Which of the following w...
- Question #375
Which of the following are the functions of a network security administrator? Each correct answer represents a complete solution. Choose three.
- Question #376
Which of the following is frequently used by administrators to verify security policies of their networks and by attackers to identify running services on a host with the view to c...
- Question #377
You need to conduct network reconnaissance, which is carried out by a remote attacker attempting to gain information or access to a network on which it is not authorized/allowed. W...
- Question #378
Which of the following arise every time an application takes a user-supplied data and sends it to a Web browser without first confirming or encoding the content?
- Question #379
How many levels of threats are faced by the SAN?
- Question #380
Which of the following components are contained in Xsan? Each correct answer represents a complete solution. Choose all that apply.
- Question #381
Which of the following statements are true about network-attached storage (NAS)? Each correct answer represents a complete solution. Choose all that apply.
- Question #382
Which of the following is an automated software testing technique that involves providing invalid, unexpected, or random data to the inputs of a computer program?
- Question #383
Which of the following statements are true about OCSP and CRL? Each correct answer represents a complete solution. Choose all that apply.
- Question #384
Which of the following is SAN management software and is designed for cross-platform workgroup collaboration?
- Question #385
End point security is an information security concept that assumes that each device (end point) is responsible for its own security. Which of the following tools are examples of en...
- Question #386
Information security continuous monitoring is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk manageme...
- Question #387
Which of the following statements are true about Continuous Monitoring? Each correct answer represents a complete solution. Choose all that apply.
- Question #388
A security engineer is troubleshooting a possible virus infection, which may have spread to multiple desktop computers within the organization. The company implements enterprise an...
- Question #389
The security administrator finds unauthorized tables and records, which were not present before, on a Linux database server. The database server communicates only with one web serv...
- Question #390
A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have ag...
- Question #391
The Information Security Officer (ISO) is reviewing new policies that have been recently made effective and now apply to the company. Upon review, the ISO identifies a new requirem...
- Question #392
The senior security administrator wants to redesign the company DMZ to minimize the risks associated with both external and internal threats. The DMZ design must support security i...
- Question #393
Company A needs to export sensitive data from its financial system to company B's database, using company B's API in an automated manner. Company A's policy prohibits the use of an...
- Question #394
Ann, a software developer, wants to publish her newly developed software to an online store. Ann wants to ensure that the software will not be modified by a third party or end user...
- Question #395
A vulnerability research team has detected a new variant of a stealth Trojan that disables itself when it detects that it is running on a virtualized environment. The team decides...
- Question #396
A system administrator is troubleshooting a possible denial of service on a sensitive system. The system seems to run properly for a few hours after it is restarted, but then it su...
- Question #397
The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function wi...
- Question #398
Which of the following activities is commonly deemed "OUT OF SCOPE" when undertaking a penetration test?
- Question #399
A sensitive database needs its cryptographic integrity upheld. Which of the following controls meets this goal? (Select TWO).
- Question #400
Some mobile devices are jail-broken by connecting via USB cable and then exploiting software vulnerabilities to get kernel-level access. Which of the following attack types represe...
- Question #401
A security company is developing a new cloud-based log analytics platform. Its purpose is to allow: - Customers to upload their log files to the "big data" platform - Customers to...
- Question #402
A penetration tester is assessing a mobile banking application. Man-in-the-middle attempts via a HTTP intercepting proxy are failing with SSL errors. Which of the following control...
- Question #403
During a software development project review, the cryptographic engineer advises the project manager that security can be greatly improved by significantly slowing down the runtime...
- Question #404
The threat abatement program manager tasked the software engineer with identifying the fastest implementation of a hash function to protect passwords with the least number of colli...
- Question #405
A security engineer at a bank has detected a Zeus variant, which relies on covert communication channels to receive new instructions and updates from the malware developers. As a r...