CAS-002 Exam Questions
884 real CAS-002 exam questions with expert-verified answers and explanations. Page 18 of 18.
- Question #864Integration of Computing, Communications and Business Disciplines
The risk manager at a small bank wants to use quantitative analysis to determine the ALE of running a business system at a location which is subject to fires during the year. A ris...
ALEquantitative risk analysisSLEARO - Question #865Integration of Computing, Communications and Business Disciplines
An accountant at a small business is trying to understand the value of a server to determine if the business can afford to buy another server for DR. The risk manager only provided...
asset valueSLEexposure factorquantitative risk - Question #866Integration of Computing, Communications and Business Disciplines
A risk manager has decided to use like lihood and consequence to determine the risk of an event occurring to a company asset. Which of the following is a limitation of this approac...
qualitative risk analysislikelihood and consequencerisk assessment limitationssubjectivity - Question #867Technical Integration of Enterprise Components
An administrator is implementing a new network-based storage device. In selecting a storage protocol, the administrator would like the data in transit's integrity to be the most im...
SMBdata integrityHMAC-SHA256storage protocols - Question #868Technical Integration of Enterprise Components
A security administrator is tasked with increasing the availability of the storage networks while enhancing the performance of existing applications. Which of the following technol...
SAN availabilitymultipath I/Odynamic disk poolsstorage performance - Question #869Technical Integration of Enterprise Components
A system administrator has just installed a new Linux distribution. The distribution is configured to be "secure out of the box". The system administrator cannot make updates to ce...
SELinuxMACLinux hardeningmandatory access control - Question #870Enterprise Security
A security solutions architect has argued consistently to implement the most secure method of encrypting corporate messages. The solution has been derided as not being cost effecti...
one-time padssymmetric encryptionkey managementcryptography - Question #871Enterprise Security
A critical system audit shows that the payroll system is not meeting security policy due to missing OS security patches. Upon further review, it appears that the system is not bein...
compensating controlsnetwork isolationunpatched systemsrisk mitigation - Question #872Integration of Computing, Communications and Business Disciplines
ODBC access to a database on a network-connected host is required. The host does not have a security mechanism to authenticate the incoming ODBC connection, and the application req...
risk acceptanceODBC securitydata ownershiprisk communication - Question #873Integration of Computing, Communications and Business Disciplines
A project manager working for a large city government is required to plan and build a WAN, which will be required to host official business and public access. It is also anticipate...
RFIprocurementWAN planningpublic sector - Question #874Enterprise Security
In a situation where data is to be recovered from an attacker's location, which of the following are the FIRST things to capture? (Select TWO).
digital forensicsvolatile dataorder of volatilityevidence collection - Question #876Integration of Computing, Communications and Business Disciplines
An information security assessor for an organization finished an assessment that identified critical issues with the human resource new employee management software application. Th...
security assessmentstakeholder engagementrisk communicationgovernance - Question #877Enterprise Security
An IT Manager is concerned about errors made during the deployment process for a new model of tablet. Which of the following would suggest best practices and configuration paramete...
deployment guidelinesconfiguration managementpolicy vs guidelineIT governance - Question #878Research and Analysis
An IT manager is concerned about the cost of implementing a web filtering solution in an effort to mitigate the risks associated with malware and resulting data leakage. Given that...
SLEALEAROrisk quantification - Question #879Integration of Computing, Communications and Business Disciplines
An IT manager is working with a project manager to implement a new ERP system capable of transacting data between the new ERP system and the legacy system. As part of this process,...
Interconnection Security AgreementISAformal agreementssystem integration - Question #880Integration of Computing, Communications and Business Disciplines
A facilities manager has observed varying electric use on the company's metered service lines. The facility management rarely interacts with the IT department unless new equipment...
change managementchange control boardresource managementIT governance - Question #881Integration of Computing, Communications and Business Disciplines
A company has a difficult time communicating between the security engineers, application developers, and sales staff. The sales staff tends to overpromise the application deliverab...
cross-functional collaborationorganizational communicationstakeholder alignmentsales and engineering - Question #882Enterprise Security
The DLP solution has been showing some unidentified encrypted data being sent using FTP to a remote server. A vulnerability scan found a collection of Linux servers that are missin...
forensic imagingincident responsevolatile memorymalware investigation - Question #883Integration of Computing, Communications and Business Disciplines
Customers have recently reported incomplete purchase history and other anomalies while accessing their account history on the web server farm. Upon investigation, it has been deter...
change controlrelease managementSDLCproduction access control - Question #884Technical Integration of Enterprise Components
A senior network security engineer has been tasked to decrease the attack surface of the corporate network. Which of the following actions would protect the external network interf...
attack surface reductionIP fragmentationnetwork scanningexternal interface hardening - Question #885Technical Integration of Enterprise Components
In an effort to minimize costs, the management of a small candy company wishes to explore a cloud service option for the development of its online applications. The company does no...
cloud computingPaaSIaaSSaaS - Question #886Technical Integration of Enterprise Components
An educational institution would like to make computer labs available to remote students. The labs are used for various IT networking, security, and programming courses. The requir...
IPSec VPNmutual authenticationRADIUSnetwork segmentation - Question #887Technical Integration of Enterprise Components
A small company is developing a new Internet-facing web application. The security requirements are: 1. Users of the web application must be uniquely identified and authenticated. 2...
OpenIDfederated authenticationweb application securityidentity management - Question #888Technical Integration of Enterprise Components
A company is trying to decide how to manage hosts in a branch location connected via a slow WAN link. The company desires to provide the same level of performance and functionality...
Read-Only Domain ControllerActive Directorybranch office securityWAN design - Question #889Enterprise Security
A multi-national company has a highly mobile workforce and minimal IT infrastructure. The company utilizes a BYOD and social media policy to integrate presence technology into glob...
presence technologyBYODphysical securityinternational travel risk - Question #890Integration of Computing, Communications and Business Disciplines
A finance manager says that the company needs to ensure that the new system can "replay" data, up to the minute, for every exchange being tracked by the investment departments. The...
requirements gatheringuser requirementsdata retentioncompliance - Question #891Integration of Computing, Communications and Business Disciplines
An IT manager is working with a project manager from another subsidiary of the same multinational organization. The project manager is responsible for a new software development ef...
time-based ACLsnetwork availabilityoutsourcingtime zone access control - Question #892Enterprise Security
The IT Security Analyst for a small organization is working on a customer's system and identifies a possible intrusion in a database that contains PII. Since PII is involved, the a...
incident responsePII breachescalation processdata breach handling - Question #893Enterprise Security
The Chief Information Security Officer (CISO) at a large organization has been reviewing some security-related incidents at the organization and comparing them to current industry...
Group Policy ObjectsUSB restrictionstechnical controlspolicy enforcement - Question #894Technical Integration of Enterprise Components
Company XYZ finds itself using more cloud-based business tools, and password management is becoming onerous. Security is important to the company; as a result, password replication...
SAMLfederated identitycloud authenticationSSO - Question #895Technical Integration of Enterprise Components
A network engineer wants to deploy user-based authentication across the company's wired and wireless infrastructure at layer 2 of the OSI model. Company policies require that users...
RADIUSLDAP802.1Xnetwork access control - Question #896Integration of Computing, Communications and Business Disciplines
A company Chief Information Officer (CIO) is unsure which set of standards should govern the company's IT policy. The CIO has hired consultants to develop use cases to test against...
security baselinesecurity standardsIT governancepolicy management - Question #897Integration of Computing, Communications and Business Disciplines
A security administrator was recently hired in a start-up company to represent the interest of security and to assist the network team in improving security in the company. The pro...
SDLCshift-left securitysecure development lifecyclesecurity by design - Question #898Research and Analysis
A well-known retailer has experienced a massive credit card breach. The retailer had gone through an audit and had been presented with a potential problem on their network. Vendors...
quantitative risk analysisresidual riskrisk calculationnetwork breach