CAS-001 Exam Questions
521 real CAS-001 exam questions with expert-verified answers and explanations. Page 9 of 11.
- Question #410Enterprise Security
An IT administrator has been tasked with implementing an appliance-based web proxy server to control external content accessed by internal staff. Concerned with the threat of corpo...
HSMSSL inspectionDLPcertificate protection - Question #411Technical Integration of Enterprise Components
A security manager is concerned about performance and patch management, and, as a result, wants to implement a virtualization strategy to avoid potential future OS vulnerabilities...
Type 1 hypervisorbare metal hypervisorparavirtualizationvirtualization security - Question #412Enterprise Security
Joe, a hacker, has discovered he can specifically craft a webpage that when viewed in a browser crashes the browser and then allows him to gain remote code execution in the context...
use-after-freeheap memory corruptionremote code executionbrowser vulnerability - Question #413Enterprise Security
A large hospital has implemented BYOD to allow doctors and specialists the ability to access patient medical records on their tablets. The doctors and specialists access patient re...
BYODmobile securityprivacymalware keylogging - Question #414Research and Analysis
A high-tech company dealing with sensitive data seized the mobile device of an employee suspected of leaking company secrets to a competitive organization. Which of the following i...
mobile forensicsevidence collectionchain of custodydigital forensics - Question #415Enterprise Security
A company is in the process of implementing a new front end user interface for its customers, the goal is to provide them with more self service functionality. The application has...
SDLC securitygrey box testingstatic code analysispenetration testing - Question #416Integration of Computing, Communications and Business Disciplines
A company is in the process of outsourcing its customer relationship management system to a cloud provider. It will host the entire organization's customer database. The database w...
cloud due diligenceright to auditvendor securitysecurity certifications - Question #417Enterprise Security
A developer is determining the best way to improve security within the code being developed. The developer is focusing on input fields where customers enter their credit card detai...
input validationregular expressionssecure codingcredit card security - Question #418Research and Analysis
The audit department at a company requires proof of exploitation when conducting internal network penetration tests. Which of the following provides the MOST conclusive proof of co...
penetration testingproof of exploitationpacket captureevidence integrity - Question #419Enterprise Security
A security administrator was doing a packet capture and noticed a system communicating with an address within the 2001::/32 prefix. The network administrator confirms there is no I...
IPv6 Teredo tunnelingcovert tunnelingfirewall rulesnetwork anomaly - Question #420Integration of Computing, Communications and Business Disciplines
An organization is finalizing a contract with a managed security services provider (MSSP) that is responsible for primary support of all security technologies. Which of the followi...
MSSPinterconnection security agreementvendor contractsmanaged security services - Question #421Enterprise Security
An administrator is trying to categorize the security impact of a database server in the case of a security event. There are three databases on the server. - Current Financial Data...
security categorizationCIA triadFIPS 199aggregate impact - Question #422Enterprise Security
Every year, the accounts payable employee, Ann, takes a week off work for a vacation. She typically completes her responsibilities remotely during this week. Which of the following...
job rotationinsider threatfraud detectionaccess control policy - Question #423Technical Integration of Enterprise Components
A new web based application has been developed and deployed in production. A security engineer decides to use an HTTP interceptor for testing the application. Which of the followin...
HTTP interceptorinput validationclient-side controlsweb application security - Question #424Enterprise Security
A security consultant is investigating acts of corporate espionage within an organization. Each time the organization releases confidential information to high-ranking engineers, t...
digital watermarkingcorporate espionagedata leakagedocument tracking - Question #425Technical Integration of Enterprise Components
A security administrator is investigating the compromise of a SCADA network that is not physically connected to any other network. Which of the following is the MOST likely cause o...
SCADA securityair gapUSB threat vectorICS compromise - Question #426Enterprise Security
The Chief Information Security Officer (CISO) at a company knows that many users store business documents on public cloud-based storage; and realizes this is a risk to the company....
risk mitigationcloud storage policysecurity awareness trainingrisk strategy - Question #427Enterprise Security
A security administrator is investigating the compromise of a software distribution website. Forensic analysis shows that several popular files are infected with malicious code. Ho...
hash collisioncryptographic hashingintegrity verificationmalware evasion - Question #428Integration of Computing, Communications and Business Disciplines
A court order has ruled that your company must surrender all the email sent and received by a certain employee for the past five years. After reviewing the backup systems, the IT a...
data retentioneDiscoverylegal compliancebackup policy - Question #429Technical Integration of Enterprise Components
A system administrator needs to meet the maximum amount of security goals for a new DNS infrastructure. The administrator deploys DNSSEC extensions to the domain names and infrastr...
DNSSECDNS securitydata integrityauthentication - Question #430Technical Integration of Enterprise Components
The risk manager is reviewing a report which identifies a requirement to keep a business critical legacy system operational for the next two years. The legacy system is out of supp...
legacy systemsnetwork segmentationend-of-life softwarerisk reduction - Question #431Technical Integration of Enterprise Components
Two separate companies are in the process of integrating their authentication infrastructure into a unified single sign-on system. Currently, both companies use an AD backend and t...
SSO federationActive Directory trustTOTPidentity integration - Question #432Integration of Computing, Communications and Business Disciplines
The Chief Risk Officer (CRO) has requested that the MTD, RTO and RPO for key business applications be identified and documented. Which of the following business documents would MOS...
BIARTORPOMTD - Question #433Integration of Computing, Communications and Business Disciplines
An organization is selecting a SaaS provider to replace its legacy, in house Customer Resource Management (CRM) application. Which of the following ensures the organization mitigat...
identity federationdirectory servicesSaaS integrationcredential management - Question #434Research and Analysis
A forensic analyst receives a hard drive containing malware quarantined by the antivirus application. After creating an image and determining the directory location of the malware...
digital forensicstimeline analysisfile system metadatamalware infection timing - Question #435Enterprise Security
After a security incident, an administrator would like to implement policies that would help reduce fraud and the potential for collusion between employees. Which of the following...
job rotationfraud preventioncollusion mitigationinsider threat - Question #436Technical Integration of Enterprise Components
A security engineer at a software development company has identified several vulnerabilities in a product late in the development cycle. This causes a huge delay for the release of...
SDLCsecure development lifecycleagile securityearly security testing - Question #437Technical Integration of Enterprise Components
Company XYZ is building a new customer facing website which must access some corporate resources. The company already has an internal facing web server and a separate server suppor...
DMZnetwork segmentationweb architectureperimeter security - Question #438Enterprise Security
A security architect is locked into a given cryptographic design based on the allowable software at the company. The key length for applications is already fixed as is the cipher a...
entropycryptographic key randomnessbrute force resistancerainbow table mitigation - Question #439Technical Integration of Enterprise Components
Noticing latency issues at its connection to the Internet, a company suspects that it is being targeted in a Distributed Denial of Service attack. A security analyst discovers nume...
NTP amplificationDDoS mitigationmonlist vulnerabilityleast-impact remediation - Question #440Technical Integration of Enterprise Components
The Chief Executive Officer (CEO) of an Internet service provider (ISP) has decided to limit the company's contribution to worldwide Distributed Denial of Service (DDoS) attacks. W...
egress filteringBCP38DDoS preventionISP security policy - Question #441Enterprise Security
For companies seeking to move to cloud services, variances in regulation between jurisdictions can be addressed in which of the following ways?
data residencycloud governancegeo-taggingregulatory compliance - Question #442Technical Integration of Enterprise Components
A large organization that builds and configures every data center against distinct requirements loses efficiency, which results in slow response time to resolve issues. However, to...
vendor diversitysingle point of failureinfrastructure riskmonoculture - Question #443Enterprise Security
The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The...
network perimeteraggregation risktelecommuting securitydefense-in-depth - Question #444Technical Integration of Enterprise Components
An industry organization has implemented a system to allow trusted authentication between all of its partners. The system consists of a web of trusted RADIUS servers communicating...
RADIUSman-in-the-middleTLSfederated authentication - Question #445Technical Integration of Enterprise Components
An organization would like to allow employees to use their network username and password to access a third-party service. The company is using Active Directory Federated Services f...
ADFSSAMLKerberosfederated identity - Question #446Enterprise Security
An extensible commercial software system was upgraded to the next minor release version to patch a security vulnerability. After the upgrade, an unauthorized intrusion into the sys...
patch managementcustom codethird-party pluginssoftware security - Question #447Enterprise Security
A security officer is leading a lessons learned meeting. Which of the following should be components of that meeting? (Select TWO).
incident responselessons learnedevent timelinefollow-up actions - Question #448Technical Integration of Enterprise Components
A network administrator with a company's NSP has received a CERT alert for targeted adversarial behavior at the company. In addition to the company's physical security, which of th...
HIDSport scanninginsider threat detectionphysical security - Question #449Enterprise Security
An administrator's company has recently had to reduce the number of Tier 3 help desk technicians available to support enterprise service requests. As a result, configuration standa...
internal reconnaissancecommand execution controlidentity managementBIOS security - Question #450Integration of Computing, Communications and Business Disciplines
A mature organization with legacy information systems has incorporated numerous new processes and dependencies to manage security as its networks and infrastructure are modernized....
Agile methodologysoftware development lifecyclerequirements managementiterative development - Question #451Enterprise Security
Joe, the Chief Executive Officer (CEO), was an Information security professor and a Subject Matter Expert for over 20 years. He has designed a network defense method which he says...
cryptographic standardsopen design principlealgorithm selectionsecurity best practices - Question #452Technical Integration of Enterprise Components
The security engineer receives an incident ticket from the helpdesk stating that DNS lookup requests are no longer working from the office. The network team has ensured that Layer...
DNS troubleshootingport scanningNMAPnetwork diagnostics - Question #453Enterprise Security
A large organization has recently suffered a massive credit card breach. During the months of Incident Response, there were multiple attempts to assign blame as to whose fault it w...
incident response phaseslessons learnedpost-incident reviewIR process - Question #454Technical Integration of Enterprise Components
A security administrator needs to deploy a remote access solution for both staff and contractors. Management favors remote desktop due to ease of use. The current risk assessment s...
RDP securityscreened subnettwo-factor authenticationremote access design - Question #455Research and Analysis
Due to compliance regulations, a company requires a yearly penetration test. The Chief Information Security Officer (CISO) has asked that it be done under a black box methodology....
black box penetration testingattacker perspectivecompliance testingpen test methodology - Question #456Technical Integration of Enterprise Components
The IT manager is evaluating IPS products to determine which would be most effective at stopping network traffic that contains anomalous content on networks that carry very specifi...
IPS typessignature-based detectionanomaly detectionnetwork traffic analysis - Question #457Enterprise Security
A software project manager has been provided with a requirement from the customer to place limits on the types of transactions a given user can initiate without external interactio...
separation of dutiesdual controlaccess controlleast privilege - Question #458Enterprise Security
Which of the following is the information owner responsible for?
data classificationinformation ownershipsecurity rolesdata governance - Question #459Enterprise Security
A Chief Information Security Officer (CISO) is approached by a business unit manager who heard a report on the radio this morning about an employee at a competing firm who shipped...
VPN authenticationmulti-factor authenticationbiometricstoken security