CAS-002 Exam Questions
884 real CAS-002 exam questions with expert-verified answers and explanations. Page 13 of 18.
- Question #610Research and Analysis
A firm's Chief Executive Officer (CEO) is concerned that its IT staff lacks the knowledge to identify complex vulnerabilities that may exist in the payment system being internally...
grey box testingNDAsecurity assurancecode confidentiality - Question #611Technical Integration of Enterprise Components
Which of the following are security components provided by an application security library or framework? (Select THREE).
application securityinput validationsecure loggingencryption - Question #612Technical Integration of Enterprise Components
A security manager is concerned about performance and patch management, and, as a result, wants to implement a virtualization strategy to avoid potential future OS vulnerabilities...
Type 1 hypervisorbare metal virtualizationparavirtualizationhypervisor architecture - Question #613Integration of Computing, Communications and Business Disciplines
An intruder was recently discovered inside the data center, a highly sensitive area. To gain access, the intruder circumvented numerous layers of physical and electronic security m...
physical securitydata center accessorganizational rolessecurity governance - Question #614Enterprise Security
A court order has ruled that your company must surrender all the email sent and received by a certain employee for the past five years. After reviewing the backup systems, the IT a...
data retentionemail archivinglegal compliancebackup policies - Question #615Technical Integration of Enterprise Components
An organization would like to allow employees to use their network username and password to access a third-party service. The company is using Active Directory Federated Services f...
federated identitySAMLKerberossingle sign-on - Question #616Enterprise Security
As a cost saving measure, a company has instructed the security engineering team to allow all consumer devices to be able to access the network. They have asked for recommendations...
BYODMDMMEAPmobile security - Question #617Enterprise Security
News outlets are beginning to report on a number of retail establishments that are experiencing payment card data breaches. The data exfiltration is enabled by malware on a comprom...
application whitelistingmalware defensethreat detectionpoint-of-sale security - Question #618Research and Analysis
Joe, the Chief Executive Officer (CEO), was an Information security professor and a Subject Matter Expert for over 20 years. He has designed a network defense method which he says...
cryptography standardsproprietary algorithmssecurity policyrisk management - Question #619Enterprise Security
The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The...
network perimeter securityrisk aggregationtelecommutingtarget value - Question #620Integration of Computing, Communications and Business Disciplines
An organization has decided to reduce labor costs by outsourcing back office processing of credit applications to a provider located in another country. Data sovereignty and privac...
data sovereigntyremote desktop securitydata exfiltration preventionthird-party risk - Question #621Technical Integration of Enterprise Components
An IT administrator has been tasked by the Chief Executive Officer with implementing security using a single device based on the following requirements: 1. Selective sandboxing of...
UTMunified threat managementsandboxingVoIP security - Question #622Technical Integration of Enterprise Components
The Chief Executive Officer (CEO) has asked the IT administrator to protect the externally facing web server from SQL injection attacks and ensure the backend database server is mo...
WAFSQL injectionDAMdatabase activity monitoring - Question #623Enterprise Security
Which of the following is the information owner responsible for?
data classificationinformation ownersecurity rolesdata governance - Question #624Enterprise Security
An administrator's company has recently had to reduce the number of Tier 3 help desk technicians available to support enterprise service requests. As a result, configuration standa...
internal reconnaissanceidentity managementBIOS securityconfiguration hardening - Question #625Technical Integration of Enterprise Components
An extensible commercial software system was upgraded to the next minor release version to patch a security vulnerability. After the upgrade, an unauthorized intrusion into the sys...
patch managementthird-party pluginscustom code vulnerabilitiesextensible software - Question #626Enterprise Security
A penetration tester is assessing a mobile banking application. Man-in-the-middle attempts via a HTTP intercepting proxy are failing with SSL errors. Which of the following control...
SSL certificate pinningmobile securityMITM preventionmobile banking - Question #627Enterprise Security
A security administrator notices a recent increase in workstations becoming compromised by malware. Often, the malware is delivered via drive-by downloads, from malware hosting web...
content filteringdrive-by downloadsmalware preventionweb security - Question #628Enterprise Security
A Chief Information Security Officer (CISO) is approached by a business unit manager who heard a report on the radio this morning about an employee at a competing firm who shipped...
multi-factor authenticationVPN securitybiometricshardware tokens - Question #629Technical Integration of Enterprise Components
The security administrator at a bank is receiving numerous reports that customers are unable to login to the bank website. Upon further investigation, the security administrator di...
DNS securityTSIGDNS poisoningtransaction signatures - Question #630Enterprise Security
A breach at a government agency resulted in the public release of top secret information. The Chief Information Security Officer has tasked a group of security professionals to dep...
MACDACBell-LaPadula modelmandatory access control - Question #631Enterprise Security
A corporate executive lost their smartphone while on an overseas business trip. The phone was equipped with file encryption and secured with a strong passphrase. The phone containe...
MDMremote wipelost devicemobile data protection - Question #632Integration of Computing, Communications and Business Disciplines
A security incident happens three times a year on a company's web server costing the company $1,500 in downtime, per occurrence. The web server is only for archival access and is s...
risk managementcost-benefit analysisALErisk treatment - Question #633Integration of Computing, Communications and Business Disciplines
The company is about to upgrade a financial system through a third party, but wants to legally ensure that no sensitive information is compromised throughout the project. The proje...
separation of dutiesNDAthird-party riskinternal controls - Question #634Technical Integration of Enterprise Components
Statement: "The system shall implement measures to notify system administrators prior to a security incident occurring." Which of the following BEST restates the above statement to...
security requirementsSDLCerror handlingrequirements translation - Question #635Enterprise Security
The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the internal network. The Chief Information Security Officer (CISO)...
risk managementmobile securityBYODrisk treatment - Question #636Technical Integration of Enterprise Components
As part of the testing phase in the SDLC, a software developer wants to verify that an application is properly handling user error exceptions. Which of the following is the BEST to...
SDLCfuzzingerror exception handlingsoftware testing - Question #637Research and Analysis
Juan is trying to perform a risk analysis of his network. He has chosen to use OCTAVE. What is OCTAVE primarily used for?
OCTAVErisk assessment methodologythreat assessmentrisk framework - Question #638Enterprise Security
Which of the following is a log that contains records of login/logout activity or other security related events specified by the systems audit policy?
security loggingaudit logsevent loggingWindows security log - Question #639Technical Integration of Enterprise Components
Which of the following is a declarative access control policy language implemented in XML and a processing model, describing how to interpret the policies?
XACMLaccess control policyXML authorizationdeclarative policy language - Question #640Integration of Computing, Communications and Business Disciplines
Which of the following is the capability to correct flows in the existing functionality without affecting other components of the system?
maintainabilitysoftware quality attributessystem designreliability - Question #642Technical Integration of Enterprise Components
Interceptor is a pseudo proxy server that performs HTTP diagnostics, which of the following features are provided by HTTP Interceptor? Each correct answer represents a complete sol...
HTTP proxyHTTP headerscookiesanonymous browsing - Question #643Enterprise Security
John is concerned about internal security threats on the network he administers. He believes that he has taken every reasonable precaution against external threats, but is concerne...
insider threatssecurity policyinternal threatsprivilege escalation - Question #644Enterprise Security
Resource exhaustion includes all of the following except_____
resource exhaustionbuffer overflowDoS attacksmemory management - Question #645Enterprise Security
Which of the following security practices are included in the Implementation phase of the Security Development Lifecycle (SDL)? Each correct answer represents a complete solution....
Security Development LifecycleSDLstatic analysisapproved tools - Question #646Technical Integration of Enterprise Components
How many levels of threats are faced by the SAN?
SAN securitystorage area networkthreat levels - Question #647Integration of Computing, Communications and Business Disciplines
Which of the following is a written document and is used in those cases where parties do not imply a legal commitment or in those situations where the parties are unable to create...
MOUlegal agreementsnon-binding agreementsbusiness documents - Question #648Enterprise Security
Which of the following statements are true about capability-based security?
capability-based securityaccess controlsecurity modelscomputing security - Question #649Technical Integration of Enterprise Components
A helpdesk manager at a financial company has received multiple reports from employees and customers that their phone calls sound metallic on the voice system. The helpdesk has bee...
VoIP securityVLAN segmentationQoSnetwork performance - Question #651Technical Integration of Enterprise Components
A new startup company with very limited funds wants to protect the organization from external threats by implementing some type of best practice security controls across a number o...
NIPSHIPSnetwork zonessecurity architecture - Question #652Enterprise Security
An administrator is reviewing logs and sees the following entry: Message: Access denied with code 403 (phase 2). Pattern match "\bunion\b.{1,100}?\bselect\b" at ARGS:$id. [data "un...
SQL injectionWAF log analysisOWASP Top 10attack identification - Question #653Research and Analysis
A University uses a card transaction system that allows students to purchase goods using their student ID. Students can put money on their ID at terminals throughout the campus. Th...
protocol analysisvulnerability researchnetwork forensicsethical hacking - Question #655Integration of Computing, Communications and Business Disciplines
In order for a company to boost profits by implementing cost savings on non-core business activities, the IT manager has sought approval for the corporate email system to be hosted...
data lifecyclecloud securitycomplianceSaaS email - Question #656Enterprise Security
A security administrator at a Lab Company is required to implement a solution which will provide the highest level of confidentiality possible to all data on the lab network. The c...
data confidentialitytransport encryptionsecurity architecturedefense in depth - Question #657Enterprise Security
An organization has had six security incidents over the past year against their main web application. Each time the organization was able to determine the cause of the incident and...
incident responserecovery timeCSIRTincident remediation - Question #658Technical Integration of Enterprise Components
A developer is coding the crypto routine of an application that will be installed on a standard headless and diskless server connected to a NAS housed in the datacenter. The develo...
cryptographic entropyheadless serverrandom number generationcryptography - Question #659Integration of Computing, Communications and Business Disciplines
Which of the following is the BEST place to contractually document security priorities, responsibilities, guarantees, and warranties when dealing with outsourcing providers?
SLAoutsourcing contractsvendor managementsecurity guarantees - Question #660Integration of Computing, Communications and Business Disciplines
Company ABC is planning to outsource its Customer Relationship Management system (CRM) and marketing / leads management to Company XYZ. Which of the following is the MOST important...
outsourcingvendor managementright to auditcontract security - Question #661Enterprise Security
A manager who was attending an all-day training session was overdue entering bonus and payroll information for subordinates. The manager felt the best way to get the changes entere...
security awareness trainingaccess controldesktop sharing policyinsider threat - Question #662Technical Integration of Enterprise Components
Which of the following precautions should be taken to harden network devices in case of VMEscape?
VM escapevirtualization securitynetwork segmentationhypervisor hardening