CAS-002 Exam Questions
884 real CAS-002 exam questions with expert-verified answers and explanations. Page 11 of 18.
- Question #508Technical Integration of Enterprise Components
You work as a Security Administrator for uCertify Inc. The company has a TCP/IP based network and uses the WS-Security service to enable message-level security for Web services. Wh...
WS-SecuritySOAPweb services securitymessage integrity - Question #509Enterprise Security
Which of the following is a key agreement protocol that allows two users to exchange a secret key over an insecure medium without any prior secrets?
Diffie-Hellmankey exchangecryptographykey agreement - Question #510Enterprise Security
Which of the following is a group of people who prepare for and respond to any emergency incident, such as a natural disaster or an interruption of business operations?
incident responseemergency managementbusiness continuityteam roles - Question #511Research and Analysis
What is this formula for SC information system = [(confidentiality, impact), (integrity, impact), (availability, impact)}?
CIA triadsecurity categorizationFIPS 199impact scoring - Question #512Enterprise Security
Mark works as a Network Security Administrator for uCertify Inc. Mark has been assigned to a task to test the network security of the company. He created a webpage to discuss the p...
social engineeringkeyloggerfirewall limitationsweb-based attack - Question #513Enterprise Security
__________ is the concept that disclosure of the long-term secret keying material that is used to derive an agreed key does not compromise the secrecy of agreed keys that had previ...
perfect forward secrecykey managementcryptographysession key protection - Question #514Technical Integration of Enterprise Components
What of the following statements is true about voice VLAN?
VLANvoice traffic segmentationnetwork designQoS - Question #515Enterprise Security
Which of the following is a version of netcat with integrated transport encryption capabilities?
Cryptcatencrypted tunnelingnetwork toolssecurity utilities - Question #516Enterprise Security
PFS depends on which type of following encryption?
perfect forward secrecyasymmetric encryptioncryptographic dependencykey exchange - Question #517Enterprise Security
The help desk is flooded with calls from users who receive an e-mail warning about a new virus. The e-mail instructs them to search and delete a number of files from their systems....
hoax attacksocial engineeringsecurity awarenessuser manipulation - Question #518Integration of Computing, Communications and Business Disciplines
Which of the following contains the complete terms and conditions which both the partners agree to be bound by as a participant in the partner program?
business partner agreementlegal contractspartner programvendor management - Question #519Research and Analysis
Denish works as a Security Administrator for a United States defense contractor. He wants to ensure that all systems have appropriate security precautions, based on their total sco...
DIACAPcompliance frameworksdefense securitysecurity standards - Question #520Integration of Computing, Communications and Business Disciplines
Which of the following department in an organization is responsible for documenting and the controlling the incoming and outgoing cash flows as well as the actual handling of the c...
organizational structurefinancial departmentcash flow managementbusiness operations - Question #521Integration of Computing, Communications and Business Disciplines
Which of the following is a legal contract between at least two parties that outlines confidential materials or knowledge the parties wish to share with one another for certain pur...
NDAlegal contractsconfidentialitydata sharing agreements - Question #522Integration of Computing, Communications and Business Disciplines
Each organization has a documented SDLC policy and guideline that supports its business needs and complements its unique culture. Which of the following should be documented in the...
SDLCsystem documentationcontrol gatesproject outputs - Question #523Enterprise Security
Which of the following statements are true about Security Requirements Traceability Matrix (SRTM)? Each correct answer represents a complete solution. Choose two.
SRTMsecurity requirementsrequirements traceabilitysecurity documentation - Question #524Technical Integration of Enterprise Components
Cloud computing is best described as which of the following?
cloud computingSaaSservice delivery modelsdistributed computing - Question #525Enterprise Security
John is hosting several Web sites on a single server. One is an e-commerce site that handles credit card transactions, while the other sites do not handle credit card data. Does th...
PCI-DSScompliancee-commerce securityweb hosting - Question #526Integration of Computing, Communications and Business Disciplines
Which of the following is a meeting of minds between two or more legally competent parties, about their relative duties and rights regarding current or future performance?
contract lawlegal agreementsservice managementparty obligations - Question #527Enterprise Security
Which of the following is a method of providing an acknowledgement to the sender of the data and an assurance of the senders identity to the receiver, so that neither sender nor th...
non-repudiationdigital signaturesauthenticationdata integrity - Question #528Integration of Computing, Communications and Business Disciplines
You are working in an organization, which has a TCP/IP based network. Each employee reports you whenever he finds a problem in the network and asks you to debug the problem, what i...
network administrationTCP/IPIT rolesnetwork troubleshooting - Question #529Integration of Computing, Communications and Business Disciplines
Which of the following statements best describe the responsibilities of a facility manager in an organization? Each correct answer represents a complete solution. Choose three.
facility managementphysical securityorganizational rolesinfrastructure planning - Question #530Technical Integration of Enterprise Components
Juan is responsible for IT security at an insurance firm. He has several severs that are going to be retired. Which of the following is NOT one of the steps in decommissioning equi...
equipment decommissioningasset lifecycleIT asset managementsecurity procedures - Question #531Enterprise Security
Mark works as a Network Security Administrator for a public school. He has decided that a hot site is appropriate for the schools grade servers, so they can have 1005= uptime, even...
hot sitedisaster recoverybusiness continuitycost-benefit analysis - Question #532Enterprise Security
In which of the following can a user access resources according to his role in the organization?
RBACaccess controlauthorizationidentity management - Question #533Integration of Computing, Communications and Business Disciplines
Which of the following phases of the System Development Life Cycle (SDLC) describes that the system should be modified on a regular basis through the addition of hardware and softw...
SDLCoperation and maintenance phasesystem lifecyclehardware upgrades - Question #534Technical Integration of Enterprise Components
Which of the following protocols encrypt the segments of network connections at the Transport Layer end-to-end? Each correct answer represents a complete solution. Choose two.
SSLTLStransport layer encryptionnetwork protocols - Question #535Enterprise Security
What routine security measure is most effective in protecting against emerging threats?
patch managementemerging threatsvulnerability mitigationsecurity controls - Question #536Research and Analysis
Which of the following governing factors should be considered to derive an overall likelihood rating that is used to specify the probability that a potential vulnerability may be e...
risk assessmentlikelihood ratingthreat-source motivationvulnerability analysis - Question #537Research and Analysis
Minimum security controls can only be determined after___________.
CIA triadsecurity baselineaggregate scoringminimum security controls - Question #538Research and Analysis
John is establishing CIA levels required for a high schools grade server. This server only has grades. It does not have student or faculty private information (such as social secur...
CIA triadconfidentialityintegrityavailability classification - Question #539Technical Integration of Enterprise Components
_________ consists of very large-scale virtualized, distributed computing systems. They cover multiple administrative domains and enable virtual organizations.
grid computingdistributed computingvirtual organizationslarge-scale infrastructure - Question #540Enterprise Security
Security Information and Event Management (SIEM) solution provides real-time analysis of security alerts generated by network hardware and applications, which of the following capa...
SIEMsecurity monitoringdata aggregationlog management - Question #541Integration of Computing, Communications and Business Disciplines
Which of the following Web sites provides a virtual community where people with a shared interest can communicate and also can post their thoughts, ideas, and anything else and sha...
social networkingweb technologiesinternet communication - Question #542Enterprise Security
Todd is a security administrator, who is responsible for responding to incidents. There has been a virus outbreak. Which of the following is the final step Todd should take?
incident responseafter action reviewpost-incident processsecurity operations - Question #543Technical Integration of Enterprise Components
In which of the following phases of the system development life cycle (SDLC) is the primary implementation of the configuration management process performed?
SDLCconfiguration managementoperation maintenancesystem lifecycle - Question #544Integration of Computing, Communications and Business Disciplines
Which of the following statements are true about mergers? Each correct answer represents a complete solution. Choose all that apply.
mergerscorporate strategyorganizational managementbusiness disciplines - Question #545Technical Integration of Enterprise Components
Which of the following refers to programs running in an isolated space to run untested code and prevents the code from making permanent changes to the OS kernel and other data on t...
application sandboxingcode isolationOS protectionmalware containment - Question #546Integration of Computing, Communications and Business Disciplines
The IT department of a large telecommunications company has developed and finalized a set of security solutions and policies which have been approved by upper management for deploy...
requirements gatheringstakeholder managementsecurity planningpolicy development - Question #547Enterprise Security
Which of the following is the MOST appropriate control measure for lost mobile devices?
mobile device managementremote wipedevice securitydata protection - Question #548Integration of Computing, Communications and Business Disciplines
A replacement CRM has had its business case approved. In preparation for a requirements workshop, an architect is working with a business analyst to ensure that appropriate securit...
security requirementsbusiness requirements documentrequirements managementCRM implementation - Question #549Technical Integration of Enterprise Components
Which of the following should be used with caution because of its ability to provide access to block level data instead of file level data?
iSCSIblock-level storagestorage protocolsSAN security - Question #550Enterprise Security
A security consultant is evaluating forms which will be used on a company website. Which of the following techniques or terms is MOST effective at preventing malicious individuals...
input validationweb application securityinjection preventionsecure coding - Question #551Enterprise Security
After implementing port security, restricting all network traffic into and out of a network, migrating to IPv6, installing NIDS, firewalls, spam and application filters, a security...
endpoint securityhost-based securityanti-malwaredefense-in-depth - Question #552Integration of Computing, Communications and Business Disciplines
The security administrator of a small private firm is researching and putting together a proposal to purchase an IPS to replace an existing IDS. A specific brand and model has been...
RFQprocurement processvendor managementcost analysis - Question #553Enterprise Security
Wireless users are reporting issues with the company's video conferencing and VoIP systems. The security administrator notices DOS attacks on the network that are affecting the com...
VoIP securityDoS attacksSIP protection802.11e QoS - Question #554Technical Integration of Enterprise Components
Company XYZ provides residential television cable service across a large region. The company's board of directors is in the process of approving a deal with the following three com...
federated identityIdP SP modeldata sharingSSO - Question #555Technical Integration of Enterprise Components
An administrator wants to virtualize the company's web servers, application servers, and database servers. Which of the following should be done to secure the virtual host machines...
virtualization securityvirtual switchhost console accesssecure management interface - Question #556Research and Analysis
A company is evaluating a new marketing strategy involving the use of social networking sites to reach its customers. The marketing director wants to be able to report important co...
social networking riskphishingsocial engineeringmalware infection - Question #557Enterprise Security
A company provides on-demand virtual computing for a sensitive project. The company implements a fully virtualized datacenter and terminal server access with two-factor authenticat...
VMEscapehypervisor securityvirtualization breachdata confidentiality