CAS-002 Exam Questions
884 real CAS-002 exam questions with expert-verified answers and explanations. Page 12 of 18.
- Question #558Technical Integration of Enterprise Components
An administrator is unable to connect to a server via VNC. Upon investigating the host firewall configuration, the administrator sees the following lines: - A INPUT -m state --stat...
iptables rulesVNC accessfirewall configurationport management - Question #559Integration of Computing, Communications and Business Disciplines
The Chief Executive Officer (CEO) has asked a security project manager to provide recommendations on the breakout of tasks for the development of a new product. The CEO thinks that...
SDLC rolesseparation of dutiessecure developmenttask assignment - Question #560Technical Integration of Enterprise Components
Company ABC has a 100Mbps fiber connection from headquarters to a remote office 200km (123 miles) away. This connection is provided by the local cable television company. ABC would...
MPLSVLAN extensionWAN protocolsnetwork tunneling - Question #561Integration of Computing, Communications and Business Disciplines
A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a...
security policy developmentregulatory compliancevendor managementpolicy framework - Question #562Enterprise Security
The Chief Information Security Officer (CISO) has just returned from attending a security conference and now wants to implement a Security Operations Center (SOC) to improve and co...
SOCSIEMthreat detectionsecurity operations - Question #563Research and Analysis
The security manager is in the process of writing a business case to replace a legacy secure web gateway so as to meet an availability requirement of 99.9% service availability. Ac...
MTBFMTTRavailability calculationreliability metrics - Question #564Enterprise Security
The security administrator has noticed a range of network problems affecting the proxy server. Based on reviewing the logs, the administrator notices that the firewall is being tar...
web attacksprotocol analyzerincident responseproxy security - Question #565Integration of Computing, Communications and Business Disciplines
Company ABC has entered into a marketing agreement with Company XYZ, whereby ABC will share some of its customer information with XYZ. However, XYZ can only contact ABC customers w...
BPAdata sharing agreementthird-party marketingcustomer data privacy - Question #566Enterprise Security
What of the following vulnerabilities is present in the below source code file named `AuthenticatedArea.php'? <html><head><title>AuthenticatedArea</title></head> <? include ("/inc/...
cross-site scriptingXSSPHP input validationsource code vulnerability - Question #567Technical Integration of Enterprise Components
An ISP is peering with a new provider and wishes to disclose which autonomous system numbers should be allowed through BGP for network transport. Which of the following should cont...
BGPInterconnection Security Agreementautonomous systemsnetwork peering - Question #568Technical Integration of Enterprise Components
Company ABC has grown yearly through mergers and acquisitions. This has led to over 200 internal custom web applications having standalone identity stores. In order to reduce costs...
centralized identity managementweb access controlfine-grained authorizationcentralized directory - Question #569Research and Analysis
Company XYZ has invested an increasing amount in security due to the changing threat landscape. The company is going through a cost cutting exercise and the Chief Financial Officer...
preventative controlsdetective controlssecurity budgetcontrols framework - Question #570Enterprise Security
Which of the following is a security concern with deploying COTS products within the network?
COTS securitythird-party software risksource code availabilityvendor software - Question #571Technical Integration of Enterprise Components
A company has a primary DNS server at address 192.168.10.53 and a secondary server at 192.168.20.53. An administrator wants to secure a company by only allowing secure zone transfe...
DNS zone transferTSIGDNS security configurationprimary secondary DNS - Question #572Technical Integration of Enterprise Components
A system architect has the following constraints from the customer: - Confidentiality, Integrity, and Availability (CIA) are all of equal importance. - Average availability must be...
high availabilitysix ninesVDI architectureCIA triad - Question #573Integration of Computing, Communications and Business Disciplines
The company's marketing department needs to provide more real-time interaction with its partners and consumers and decides to move forward with a presence on multiple social networ...
social media policyinformation disclosuresecurity trainingdata governance - Question #574Research and Analysis
A security manager at Company ABC, needs to perform a risk assessment of a new mobile device which the Chief Information Officer (CIO) wants to immediately deploy to all employees...
mobile device securityMDMrisk assessmentremote wipe - Question #575Technical Integration of Enterprise Components
A security administrator has finished building a Linux server which will host multiple virtual machines through hypervisor technology. Management of the Linux server, including mon...
virtualization securitychroot jailhypervisorweb application vulnerability - Question #576Enterprise Security
A web administrator develops a web form for users to respond to the company via a web page. Which of the following should be practiced to avoid a security risk?
input validationweb securityXSSSQL injection - Question #577Technical Integration of Enterprise Components
A manufacturing company is having issues with unauthorized access and modification of the controls operating the production equipment. A communication requirement is to allow the f...
SCADA securityICSAAAaccess control - Question #578Research and Analysis
A security analyst at Company A has been trying to convince the Information Security Officer (ISO) to allocate budget towards the purchase of a new intrusion prevention system (IPS...
IPSthreat intelligencebusiness caserisk analysis - Question #579Enterprise Security
Which of the following is the MOST cost-effective solution for sanitizing a DVD with sensitive information on it?
media sanitizationdata destructionoptical mediaDVD - Question #580Research and Analysis
An organization must comply with a new regulation that requires the organization to determine if an external attacker is able to gain access to its systems from outside the network...
penetration testingblack box testingcomplianceexternal threats - Question #581Enterprise Security
The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the company's internal network. The Chief Information Security Offi...
mobile device securityencryptionPIN authenticationBYOD - Question #582Enterprise Security
An Information Security Officer (ISO) has asked a security team to randomly retrieve discarded computers from the warehouse dumpster. The security team was able to retrieve two old...
hardware decommissioningdata sanitizationmedia disposalMFD - Question #583Integration of Computing, Communications and Business Disciplines
A company has asked their network engineer to list the major advantages for implementing a virtual environment in regards to cost. Which of the following would MOST likely be selec...
virtualizationcost reductionphysical footprintdata center - Question #584Research and Analysis
Company XYZ has purchased and is now deploying a new HTML5 application. The company wants to hire a penetration tester to evaluate the security of the client and server components...
web application testingblack box testingfuzzinglocal proxy - Question #585Enterprise Security
A company has been purchased by another agency and the new security architect has identified new security goals for the organization. The current location has video surveillance th...
physical access controltwo-factor authenticationbiometricsproximity readers - Question #586Enterprise Security
Continuous monitoring is a popular risk reduction technique in many large organizations with formal certification processes for IT projects. In order to implement continuous monito...
continuous monitoringlog managementSIEMsecurity operations - Question #587Technical Integration of Enterprise Components
A systems administrator establishes a CIFS share on a Unix device to share data to windows systems. The security authentication on the windows domain is set to the highest level. W...
CIFSNTLMv2cross-platform authenticationSMB security - Question #588Integration of Computing, Communications and Business Disciplines
A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still f...
patch managementsecurity controlsaudit findingsrisk management - Question #589Enterprise Security
A company's security policy states that its own internally developed proprietary Internet facing software must be resistant to web application attacks. Which of the following metho...
secure codingweb application securitydatabase protectionSQL injection - Question #590Integration of Computing, Communications and Business Disciplines
A medium-sized company has recently launched an online product catalog. It has decided to keep the credit card purchasing in-house as a secondary potential income stream has been i...
PCI DSScomplianceindustry standardscredit card security - Question #591Research and Analysis
Company XYZ is in negotiations to acquire Company ABC for $1.2millon. Due diligence activities have uncovered systemic security issues in the flagship product of Company ABC. It ha...
risk avoidancedue diligenceM&A securityrisk management - Question #592Technical Integration of Enterprise Components
A UNIX administrator notifies the storage administrator that extra LUNs can be seen on a UNIX server. The LUNs appear to be NTFS file systems. Which of the following MOST likely ha...
SAN storageHBA allocationLUNiSCSI - Question #594Enterprise Security
The internal audit department is investigating a possible breach of security. One of the auditors is sent to interview the following employees: Employee A. Works in the accounts re...
separation of dutiesleast privilegeaccess controlfinance security - Question #595Enterprise Security
A new IDS device is generating a very large number of irrelevant events. Which of the following would BEST remedy this problem?
IDS tuningfalse positivesintrusion detectionalert management - Question #596Research and Analysis
An organization is preparing to upgrade its firewall and NIPS infrastructure and has narrowed the vendor choices down to two platforms. The integrator chosen to assist the organiza...
vendor evaluationfirewallNIPSsecurity testing methodology - Question #597Enterprise Security
Company XYZ has had repeated vulnerability exploits of a critical nature released to the company's flagship product. The product is used by a number of large customers. At the Chie...
product security lifecyclevulnerability managementstrategic securitySDLC - Question #598Technical Integration of Enterprise Components
SDLC is being used for the commissioning of a new platform. To provide an appropriate level of assurance the security requirements that were specified at the project origin need to...
SRTMSDLCsecurity requirements traceabilityrequirements management - Question #599Integration of Computing, Communications and Business Disciplines
The security administrator is receiving numerous alerts from the internal IDS of a possible Conficker infection spreading through the network via the Windows file sharing services....
change managementincident responseACLConficker - Question #600Enterprise Security
An internal employee has sold a copy of the production customer database that was being used for upgrade testing to outside parties via HTTP file upload. The Chief Information Offi...
data loss preventioninsider threatdata exfiltrationDLP - Question #601Technical Integration of Enterprise Components
The security administrator is worried about possible SPIT attacks against the VoIP system. Which of the following security controls would MOST likely need to be implemented to dete...
SPITVoIP securitySIPSRTP - Question #602Research and Analysis
A security administrator has been conducting a security assessment of Company XYZ for the past two weeks. All of the penetration tests and other assessments have revealed zero flaw...
social engineeringpenetration testingdata exfiltrationsecurity assessment - Question #603Research and Analysis
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which...
risk analysisimpact assessmentrisk acceptancevulnerability management - Question #605Enterprise Security
A user reports that the workstation's mouse pointer is moving and files are opening automatically. Which of the following should the user perform?
incident responseremote access trojanmalwaresecurity procedures - Question #606Technical Integration of Enterprise Components
Company A is purchasing Company B, and will import all of Company B's users into its authentication system. Company A uses 802.1x with a RADIUS server, while Company B uses a capti...
802.1xRADIUSLDAPnetwork authentication integration - Question #607Integration of Computing, Communications and Business Disciplines
A bank has just outsourced the security department to a consulting firm, but retained the security architecture group. A few months into the contract the bank discovers that the co...
third-party riskoutsourcingcontract managementvendor governance - Question #608Research and Analysis
A database is hosting information assets with a computed CIA aggregate value of high. The database is located within a secured network zone where there is flow control between the...
insider threatprivileged accessdatabase securitythreat analysis - Question #609Enterprise Security
Which of the following activities could reduce the security benefits of mandatory vacations?
mandatory vacationfraud detectionseparation of dutiespersonnel security