CAS-001 Exam Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 8 of 11.
- Question #360Technical Integration of Enterprise Components
Which of the following components of a VoIP network is frequently used to bridge video conferencing connections?
VoIPMCUvideo conferencingnetwork components - Question #361Enterprise Security
Which of the following is a declarative access control policy language implemented in XML and a processing model, describing how to interpret the policies?
XACMLaccess control policyXMLauthorization language - Question #362Enterprise Security
You want to allow some users to access a particular program on the computers in the network. What will you do to accomplish this task?
group policyaccess controlnetwork administrationuser permissions - Question #363Enterprise Security
Which of the following is the most secure authentication scheme and uses a public key cryptography and digital certificate to authenticate a user?
certificate-based authenticationPKIdigital certificatepublic key cryptography - Question #364Enterprise Security
Which of the following security practices are included in the Implementation phase of the Security Development Lifecycle (SDL)? Each correct answer represents a complete solution....
SDLsecurity development lifecyclestatic analysisimplementation phase - Question #365Research and Analysis
In which of the following activities an organization identifies and prioritizes technical, organizational, procedural, administrative, and physical security weaknesses?
vulnerability assessmentsecurity assessmentrisk identificationpenetration testing - Question #366Enterprise Security
SDLC phases include a minimum set of security tasks that are required to effectively incorporate security in the system development process. Which of the following are the key secu...
SDLCdevelopment phase securityrisk assessmentsystem accreditation - Question #367Technical Integration of Enterprise Components
Which of the following is an XML-based framework developed by OASIS and used to exchange user, resource and service provisioning information between cooperating organizations?
SPMLOASISXML provisioningidentity federation - Question #368Integration of Computing, Communications and Business Disciplines
Which of the following terms is about communicating the user's need and ability to communicate, and the medium through which that communication may occur?
presence technologyunified communicationscollaborationcommunication medium - Question #369Technical Integration of Enterprise Components
Which technology can be used to help ensure the efficient transport of VoIP traffic?
QoSVoIPtraffic prioritizationnetwork transport - Question #370Enterprise Security
In which of the following attacks does an attacker intercept call-signaling SIP message traffic and masquerade as the calling party to the called party and vice-versa?
man-in-the-middleSIPVoIP securitycall signaling attack - Question #371Technical Integration of Enterprise Components
Which of the following protocols is used extensively in communication and entertainment systems that involve streaming media, such as telephony, video teleconference applications a...
RTPstreaming mediaVoIP protocolmultimedia transport - Question #372Integration of Computing, Communications and Business Disciplines
Collaboration platform offers a set of software components and services that enable users to communicate, share information, and work together for achieving common business goals....
collaboration platformreal-time communicationteam collaborationmessaging - Question #373Integration of Computing, Communications and Business Disciplines
Which of the following stages are involved in the successful implementation of a collaboration platform? Each correct answer represents a part of the solution. Choose two.
collaboration platformimplementation stagessolution designplatform deployment - Question #374Enterprise Security
You want the clients and servers in your organization to be able to communicate in a way that prevents eavesdropping and tampering of data on the Internet. Which of the following w...
SSLencryptioneavesdropping preventiondata in transit - Question #375Enterprise Security
Which of the following are the functions of a network security administrator? Each correct answer represents a complete solution. Choose three.
network security administrationfirewall managementIT security policysecurity roles - Question #376Research and Analysis
Which of the following is frequently used by administrators to verify security policies of their networks and by attackers to identify running services on a host with the view to c...
port scannernetwork reconnaissancesecurity testingservice enumeration - Question #377Research and Analysis
You need to conduct network reconnaissance, which is carried out by a remote attacker attempting to gain information or access to a network on which it is not authorized/allowed. W...
network reconnaissancevulnerability scannerunauthorized accessattacker techniques - Question #378Enterprise Security
Which of the following arise every time an application takes a user-supplied data and sends it to a Web browser without first confirming or encoding the content?
XSScross-site scriptingweb application securityinput validation - Question #379Technical Integration of Enterprise Components
How many levels of threats are faced by the SAN?
SANstorage area networkthreat levelsstorage security - Question #380Technical Integration of Enterprise Components
Which of the following components are contained in Xsan? Each correct answer represents a complete solution. Choose all that apply.
XsanSAN componentsmetadata controllerstorage network - Question #381Technical Integration of Enterprise Components
Which of the following statements are true about network-attached storage (NAS)? Each correct answer represents a complete solution. Choose all that apply.
NASfile-based protocolsNFSSMB/CIFS - Question #382Research and Analysis
Which of the following is an automated software testing technique that involves providing invalid, unexpected, or random data to the inputs of a computer program?
fuzzingsoftware testingrandom inputvulnerability testing - Question #383Enterprise Security
Which of the following statements are true about OCSP and CRL? Each correct answer represents a complete solution. Choose all that apply.
OCSPCRLcertificate revocationPKI - Question #384Technical Integration of Enterprise Components
Which of the following is SAN management software and is designed for cross-platform workgroup collaboration?
SANMetaSANstorage managementcross-platform collaboration - Question #385Enterprise Security
End point security is an information security concept that assumes that each device (end point) is responsible for its own security. Which of the following tools are examples of en...
endpoint securityanti-malwareanti-virusspam filters - Question #386Enterprise Security
Information security continuous monitoring is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk manageme...
continuous monitoringsecurity controls assessmentconfiguration managementrisk management - Question #387Enterprise Security
Which of the following statements are true about Continuous Monitoring? Each correct answer represents a complete solution. Choose all that apply.
continuous monitoringsystem accreditationsecurity lifecyclefederal compliance - Question #388Enterprise Security
A security engineer is troubleshooting a possible virus infection, which may have spread to multiple desktop computers within the organization. The company implements enterprise an...
cloud-augmented securityantivirus evasionfirewall log analysiszero-day threat - Question #389Enterprise Security
The security administrator finds unauthorized tables and records, which were not present before, on a Linux database server. The database server communicates only with one web serv...
SQL injectionprivilege escalationpath traversalweb server log analysis - Question #390Integration of Computing, Communications and Business Disciplines
A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have ag...
business acquisitionregulatory complianceIT integrationoperational procedures - Question #391Enterprise Security
The Information Security Officer (ISO) is reviewing new policies that have been recently made effective and now apply to the company. Upon review, the ISO identifies a new requirem...
policy exceptiontwo-factor authenticationrisk justificationcompensating controls - Question #392Technical Integration of Enterprise Components
The senior security administrator wants to redesign the company DMZ to minimize the risks associated with both external and internal threats. The DMZ design must support security i...
DMZ designdual firewallsecurity in depthincident reconstruction - Question #393Technical Integration of Enterprise Components
Company A needs to export sensitive data from its financial system to company B's database, using company B's API in an automated manner. Company A's policy prohibits the use of an...
end-to-end encryptionSSL tunnelinglegacy system integrationAPI security - Question #394Enterprise Security
Ann, a software developer, wants to publish her newly developed software to an online store. Ann wants to ensure that the software will not be modified by a third party or end user...
remote attestationmobile securitycode integritysoftware signing - Question #395Research and Analysis
A vulnerability research team has detected a new variant of a stealth Trojan that disables itself when it detects that it is running on a virtualized environment. The team decides...
packet analyzermalware analysisstealth Trojannetwork forensics - Question #396Enterprise Security
A system administrator is troubleshooting a possible denial of service on a sensitive system. The system seems to run properly for a few hours after it is restarted, but then it su...
garbage collectionmemory leakinsider threatdenial of service - Question #397Integration of Computing, Communications and Business Disciplines
The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function wi...
risk transferBIArisk managementbusiness continuity - Question #398Research and Analysis
Which of the following activities is commonly deemed "OUT OF SCOPE" when undertaking a penetration test?
penetration testingdenial of servicescope definitionrules of engagement - Question #399Enterprise Security
A sensitive database needs its cryptographic integrity upheld. Which of the following controls meets this goal? (Select TWO).
data signingcryptographic integrityRBACdatabase security - Question #400Enterprise Security
Some mobile devices are jail-broken by connecting via USB cable and then exploiting software vulnerabilities to get kernel-level access. Which of the following attack types represe...
physical attackprivilege escalationmobile jailbreakkernel exploitation - Question #401Enterprise Security
A security company is developing a new cloud-based log analytics platform. Its purpose is to allow: - Customers to upload their log files to the "big data" platform - Customers to...
multi-tenancyRBACAPI securitycloud data protection - Question #402Enterprise Security
A penetration tester is assessing a mobile banking application. Man-in-the-middle attempts via a HTTP intercepting proxy are failing with SSL errors. Which of the following control...
SSL certificate pinningmobile securityMITM preventionTLS - Question #403Enterprise Security
During a software development project review, the cryptographic engineer advises the project manager that security can be greatly improved by significantly slowing down the runtime...
key stretchingpassword hashingsaltcryptography - Question #404Enterprise Security
The threat abatement program manager tasked the software engineer with identifying the fastest implementation of a hash function to protect passwords with the least number of colli...
password hashingSHA-512salthash functions - Question #405Enterprise Security
A security engineer at a bank has detected a Zeus variant, which relies on covert communication channels to receive new instructions and updates from the malware developers. As a r...
steganographycovert channelsmalwareZeus botnet - Question #406Enterprise Security
A security engineer wants to implement forward secrecy but still wants to ensure the number of requests handled by the web server is not drastically reduced due to the larger compu...
forward secrecyECDHETLS key exchangeperformance - Question #407Technical Integration of Enterprise Components
An IT administrator has been tasked by the Chief Executive Officer with implementing security using a single device based on the following requirements: 1.Selective sandboxing of s...
UTMsandboxingVoIP securityunified threat management - Question #408Technical Integration of Enterprise Components
The Chief Executive Officer (CEO) has asked the IT administrator to protect the externally facing web server from SQL injection attacks and ensure the backend database server is mo...
WAFDAMSQL injectiondatabase security - Question #409Technical Integration of Enterprise Components
The risk manager has requested a security solution that is centrally managed, can easily be updated, and protects end users' workstations from both known and unknown malicious atta...
HIPSendpoint securitythreat protectioncentralized management