CAS-002 Exam Questions
884 real CAS-002 exam questions with expert-verified answers and explanations. Page 2 of 18.
- Question #51Integration of Computing, Communications and Business Disciplines
A Chief Information Security Officer (CISO) has been trying to eliminate some IT security risks for several months. These risks are not high profile but still exist. Furthermore, m...
risk acceptancerisk strategybudget constraintsrisk management - Question #52Technical Integration of Enterprise Components
A company is planning to deploy an in-house Security Operations Center (SOC). One of the new requirements is to deploy a NIPS solution into the Internet facing environment. The SOC...
NIPS placementDMZ architecturefirewall topologynetwork security - Question #53Technical Integration of Enterprise Components
A security administrator wants to perform an audit of the company password file to ensure users are not using personal information such as addresses and birthdays as part of their...
password auditingcluster computingdistributed computingcloud resources - Question #54Enterprise Security
An ecommerce application on a Linux server does not properly track the number of incoming connections to the server and may leave the server vulnerable to which of following?
DoS attackconnection trackingweb application vulnerabilityavailability - Question #55Technical Integration of Enterprise Components
The network administrator has been tracking the cause of network performance problems and decides to take a look at the internal and external router stats. Which of the following s...
QoSIP TOS fieldnetwork performancetraffic prioritization - Question #56Enterprise Security
A new malware spreads over UDP Port 8320 and several network hosts have been infected. A new security administrator has determined a possible cause, and the infected machines have...
firewall rulesmalware mitigationUDP filteringdeny-all policy - Question #57Integration of Computing, Communications and Business Disciplines
At one time, security architecture best practices led to networks with a limited number (1-3) of network access points. This restriction allowed for the concentration of security r...
security architecture evolutionnetwork perimeterattack surfacecloud and mobile impact - Question #58Enterprise Security
Company A is trying to implement controls to reduce costs and time spent on litigation. To accomplish this, Company A has established several goals: - Prevent data breaches from lo...
DLPencryptionseparation of dutiese-discovery - Question #59Integration of Computing, Communications and Business Disciplines
Company A is merging with Company B. Company B uses mostly hosted services from an outside vendor, while Company A uses mostly in-house products. The project manager of the merger...
IT outsourcingcost-benefit analysismerger integrationstaff capacity - Question #60Technical Integration of Enterprise Components
A corporation relies on a server running a trusted operating system to broker data transactions between different security zones on their network. Each zone is a separate domain an...
network zone segmentationNIPStrusted OSmulti-zone architecture - Question #61Research and Analysis
A security architect is seeking to outsource company server resources to a commercial cloud service provider. The provider under consideration has a reputation for poorly controlli...
cloud securitymulti-tenancyrisk assessmentsocial engineering - Question #62Technical Integration of Enterprise Components
Virtual hosts with different security requirements should be:
virtualizationVM isolationphysical separationsecurity zones - Question #63Research and Analysis
The company is considering issuing non-standard tablet computers to executive management. Which of the following is the FIRST step the security manager should perform?
mobile device managementrisk analysisBYODexecutive access - Question #64Enterprise Security
An employee of a company files a complaint with a security administrator. While sniffing network traffic, the employee discovers that financially confidential emails were passing b...
non-repudiationdigital signaturestransport encryptionemail security - Question #65Integration of Computing, Communications and Business Disciplines
Company XYZ is selling its manufacturing business consisting of one plant to a competitor, Company QRS. All of the people will become QRS employees, but will retain permissions to...
network co-minglingM&A securityaccess controldata exfiltration - Question #66Technical Integration of Enterprise Components
A programming team is deploying a new PHP module to be run on a Solaris 10 server with trusted extensions. The server is configured with three zones, a management zone, a customer...
Solaris zonestrusted extensionszone isolationapplication deployment - Question #67Technical Integration of Enterprise Components
An administrator is troubleshooting availability issues on a FCoE based storage array that uses deduplication. An administrator has access to the raw data from the SAN and wants to...
SAN storageFCoEdeduplicationdata recovery - Question #68Research and Analysis
During user acceptance testing, the security administrator believes to have discovered an issue in the login prompt of the company's financial system. While entering the username a...
fuzzingapplication security testinginput validationvulnerability reproduction - Question #69Enterprise Security
Which of the following is a security advantage of single sign-on? (Select TWO).
SSOidentity managementauthenticationaccess revocation - Question #70Technical Integration of Enterprise Components
A small company has recently placed a newly installed DNS server on the DMZ and wants to secure it by allowing Internet hosts to query the DNS server. Since the company deploys an...
DNS securityfirewall ACLDMZ configurationport filtering - Question #71Enterprise Security
Security is one of the most important issues an organization must discuss. Mitch wants security that is built into an application. Why would this be a problem?
application securityperimeter securitydefense in depth - Question #72Enterprise Security
David is a security administrator at his organization. He is trying to prevent unauthorized access to the corporate wireless network by people loafing around the office. What kind...
wireless securitywar drivingunauthorized access - Question #73Technical Integration of Enterprise Components
You have entered information in the database. It has been changed and is reflected in the database. What has been done?
database transactionscommitDBMS operations - Question #74Technical Integration of Enterprise Components
Database models define the relationship between different data elements, dictate how data can be accessed and define acceptable operations, the type of integrity offered, and how t...
relational databasedata modelsattributes and tuples - Question #75Integration of Computing, Communications and Business Disciplines
George is reading a publication on ethics-related statements concerning the use of the Internet. Who wrote this statement?
IABinternet ethicsgovernancepolicy - Question #76Technical Integration of Enterprise Components
What is a single link that is pre-established for the purposes of WAN communications between two destinations?
WANdedicated linksnetwork connectivity - Question #77Enterprise Security
Which of the following statements regarding the MD5 algorithm is NOT true?
MD5hashing algorithmsone-way hashcryptography - Question #78Enterprise Security
What is the type of software that is installed on someone's computer without their knowledge?
malwarespywareadwareunauthorized software - Question #79Research and Analysis
There have been some failures of the company's customer-facing website. A security engineer has analyzed the root cause to be the WAF. System logs show that the WAF has been down f...
MTTRavailability metricsWAFincident management - Question #80Research and Analysis
Which of the following is the MOST secure way to ensure third party applications and introduce only acceptable risk?
third-party softwarecode reviewsupply chain securityrisk acceptance - Question #81Technical Integration of Enterprise Components
To prevent a third party from identifying a specific user as having previously accessed a service provider through an SSO operation, SAML uses which of the following?
SAMLSSO privacytransient identifiersfederation - Question #82Technical Integration of Enterprise Components
An administrator implements a new PHP application into an existing website and discovers the newly added PHP pages do not work. The rest of the site also uses PHP and is functionin...
SELinuxApache configurationPHPmandatory access control - Question #83Enterprise Security
After a system update causes significant downtime, the Chief Information Security Officer (CISO) asks the IT manager who was responsible for the update. The IT manager responds tha...
change managementuser auditingaccountabilityadministrative access - Question #84Technical Integration of Enterprise Components
A storage administrator would like to make storage available to some hosts and unavailable to other hosts. Which of the following would be used?
LUN maskingSANstorage access controlhost isolation - Question #85Technical Integration of Enterprise Components
The IT Manager has mandated that an extensible markup language be implemented which can be used to exchange provisioning requests and responses for account creation. Which of the f...
SPMLidentity provisioningXMLaccount lifecycle - Question #86Integration of Computing, Communications and Business Disciplines
The firm's CISO has been working with the Chief Procurement Officer (CPO) and the Senior Project Manager (SPM) on soliciting bids for a series of HIPS and NIPS products for a major...
procurementRFIRFQvendor management - Question #87Technical Integration of Enterprise Components
A company data center provides Internet based access to email and web services. The firewall is separated into four zones: RED ZONE is an Internet zone ORANGE ZONE a Web DMZ YELLOW...
network security zonesNIPSDMZ architecturesecurity appliance placement - Question #88Technical Integration of Enterprise Components
An administrator wants to integrate the Credential Security Support Provider (CredSSP) protocol network level authentication (NLA) into the remote desktop terminal services environ...
CredSSPNLAremote desktopauthentication protocols - Question #89Enterprise Security
A company decides to purchase COTS software. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?
COTS softwarevendor risksoftware acquisitionnetwork security - Question #90Enterprise Security
The increasing complexity of attacks on corporate networks is a direct result of more and more corporate employees connecting to corporate networks with mobile and personal devices...
BYODmobile securitydata exfiltrationMDM - Question #91Technical Integration of Enterprise Components
When planning a complex system architecture, it is important to build in mechanisms to secure log information, facilitate audit log reduction, and event correlation. Besides synchr...
SIEMlog managementNTPcentralized logging - Question #92Integration of Computing, Communications and Business Disciplines
A financial institution has decided to purchase a very expensive resource management system and has selected the product and vendor. The vendor is experiencing some minor, but publ...
source code escrowvendor riskthird-party contractsbusiness continuity - Question #93Enterprise Security
During a specific incident response and recovery process action, the response team determines that it must first speak to the person ultimately responsible for the data. With whom...
data ownershipincident responsedata classificationroles and responsibilities - Question #94Enterprise Security
After a recent outbreak of malware attacks, the Chief Information Officer (CIO) tasks the new security manager with determining how to keep these attacks from reoccurring. The comp...
malware preventionvulnerability assessmentendpoint securitysecurity hardening - Question #95Integration of Computing, Communications and Business Disciplines
To support a software security initiative business case, a project manager needs to provide a cost benefit analysis. The project manager has asked the security consultant to perfor...
ROIcost-benefit analysissecurity investmentfinancial analysis - Question #96Technical Integration of Enterprise Components
A network security engineer would like to allow authorized groups to access network devices with a shell restricted to only show information while still authenticating the administ...
TACACS+RADIUSAAAshell restriction - Question #97Enterprise Security
SAML entities can operate in a variety of different roles. Valid SAML roles include which of the following?
SAMLidentity providerservice providerfederation - Question #98Enterprise Security
When authenticating over HTTP using SAML, which of the following is issued to the authenticating user?
SAMLassertion ticketHTTP authenticationSSO - Question #99Technical Integration of Enterprise Components
An existing enterprise architecture included an enclave where sensitive research and development work was conducted. This network enclave also served as a storage location for prop...
network segmentationde-perimeterizationenterprise architectureenclave design - Question #100Enterprise Security
A legacy system is not scheduled to be decommissioned for two years and requires the use of the standard Telnet protocol. Which of the following should be used to mitigate the secu...
legacy systemsTelnetVLAN segmentationnetwork isolation