CAS-002 Exam Questions
884 real CAS-002 exam questions with expert-verified answers and explanations. Page 3 of 18.
- Question #101Research and Analysis
A systems security consultant is hired by Corporation X to analyze the current enterprise network environment and make recommendations for increasing network security. It is the co...
security assessmentbusiness requirementsthreat analysisnetwork design - Question #102Enterprise Security
The Chief Information Officer (CIO) of Company XYZ has returned from a large IT conference where one of the topics was defending against zero day attacks specifically deploying thi...
zero-day vulnerabilitiesthird-party patchespatch managementrisk analysis - Question #103Research and Analysis
The security administrator at `company.com' is reviewing the network logs and notices a new UDP port pattern where the amount of UDP port 123 packets has increased by 20% above the...
NTPpacket analysisanomaly detectionnetwork forensics - Question #104Enterprise Security
In order to reduce cost and improve employee satisfaction, a large corporation has decided to allow personal communication devices to access email and to remotely connect to the co...
BYODdevice lockdownremote accessdata encryption in transit - Question #105Enterprise Security
The root cause analysis of a recent security incident reveals that an attacker accessed a printer from the Internet. The attacker then accessed the print server, using the printer...
privilege escalationlateral movementincident mitigationattack chain analysis - Question #106Technical Integration of Enterprise Components
A company has recently implemented a video conference solution that uses the H.323 protocol. The security engineer is asked to make recommendations on how to secure video conferenc...
H.323H.235video conferencing securitytransport encryption - Question #107Enterprise Security
A growing corporation is responding to the needs of its employees to access corporate email and other resources while traveling. The company is implementing remote access for compa...
VPNmultifactor authenticationremote accessmobile workforce - Question #108Technical Integration of Enterprise Components
An administrator would like to connect a server to a SAN. Which of the following processes would BEST allow for availability and access control?
SANLUN maskingHBAstorage access control - Question #109Enterprise Security
Unit testing for security functionality and resiliency to attack, as well as developing secure code and exploit mitigation, occur in which of the following phases of the Secure Sof...
SSDLCsecure software implementationunit testingexploit mitigation - Question #110Technical Integration of Enterprise Components
A security engineer at a major financial institution is prototyping multiple secure network configurations. The testing is focused on understanding the impact each potential design...
security lifecyclenetwork designdecommissioningfinancial compliance - Question #112Integration of Computing, Communications and Business Disciplines
Customer Need: "We need the system to produce a series of numbers with no discernible mathematical progression for use by our Java based, PKI-enabled, customer facing website." Whi...
PRNGPKIrequirements translationrandom number generation - Question #113Technical Integration of Enterprise Components
A startup company offering software on demand has hired a security consultant to provide expertise on data security. The company's clients are concerned about data confidentiality....
data confidentialityvirtualizationmulti-tenancycloud security - Question #114Technical Integration of Enterprise Components
The <nameID> element in SAML can be provided in which of the following predefined formats? (Select TWO).
SAMLnameID formatsX.509Kerberos - Question #115Research and Analysis
A security researcher is about to evaluate a new secure VoIP routing appliance. The appliance manufacturer claims the new device is hardened against all known attacks and several u...
device fingerprintingVoIP securityport enumerationappliance assessment - Question #116Enterprise Security
A network administrator notices a security intrusion on the web server. Which of the following is noticed by file?
XSSweb application attacksintrusion detectionfile-based detection - Question #117Research and Analysis
The Chief Information Security Officer (CISO) of a small bank wants to embed a monthly testing regiment into the security management plan specifically for the development area. The...
white box testingsoftware assurancetesting methodologydevelopment security - Question #118Enterprise Security
A database administrator comes across the below records in one of the databases during an internal audit of the payment system: UserIDAddressCredit Card No.Password jsmith123 fake...
password storagePCI-DSSdatabase securityplaintext credentials - Question #119Integration of Computing, Communications and Business Disciplines
A company is preparing to upgrade its NIPS at five locations around the world. The three platforms the team plans to test, claims to have the most advanced features and lucrative p...
NIPStotal cost of ownershipplatform selectionprocurement - Question #120Integration of Computing, Communications and Business Disciplines
A corporation has expanded for the first time by integrating several newly acquired businesses. Which of the following are the FIRST tasks that the security team should undertake?...
mergers and acquisitionsrisk analysisinterconnection policyenterprise integration - Question #121Research and Analysis
An administrator receives reports that the network is running slow for users connected to a certain switch. Viewing the network traffic, the administrator reviews the following: 18...
DNS PTR queriestraffic analysisnetwork zoningpacket capture - Question #122Integration of Computing, Communications and Business Disciplines
The security administrator at a company has received a subpoena for the release of all the email received and sent by the company Chief Information Officer (CIO) for the past three...
data retentionlegal complianceemail recordsbackup archives - Question #123Enterprise Security
Staff from the sales department have administrator rights to their corporate standard operating environment, and often connect their work laptop to customer networks when onsite du...
NACendpoint securityprivileged accessnetwork access control - Question #124Enterprise Security
A morphed worm carrying a 0-day payload has infiltrated the company network and is now spreading across the organization. The security administrator was able to isolate the worm co...
worm mitigationHIPSACLincident response - Question #125Enterprise Security
An intrusion detection system logged an attack attempt from a remote IP address. One week later, the attacker successfully compromised the network. Which of the following MOST like...
IDSlog monitoringfalse positivesincident response - Question #126Technical Integration of Enterprise Components
A small company hosting multiple virtualized client servers on a single host is considering adding a new host to create a cluster. The new host hardware and operating system will b...
high availabilityvirtualization clusteringiSCSIshared storage - Question #127Enterprise Security
The risk committee has endorsed the adoption of a security system development life cycle (SSDLC) designed to ensure compliance with PCI-DSS, HIPAA, and meet the organization's miss...
SSDLC phasesPCI-DSSHIPAAsecurity lifecycle - Question #129Integration of Computing, Communications and Business Disciplines
Within the company, there is executive management pressure to start advertising to a new target market. Due to the perceived schedule and budget inefficiencies of engaging a techno...
third-party riskoutsourcing securitycontractual obligationsrisk management - Question #130Technical Integration of Enterprise Components
Company A has a remote work force that often includes independent contractors and out of state full time employees. Company A's security engineer has been asked to implement a solu...
SSL VPNvirtual desktopremote accessdata residency - Question #131Integration of Computing, Communications and Business Disciplines
A large corporation which is heavily reliant on IT platforms and systems is in financial difficulty and needs to drastically reduce costs in the short term to survive. The Chief Fi...
IT outsourcingstrategic architecturesegregation of dutiesvendor management - Question #132Enterprise Security
As part of the ongoing information security plan in a large software development company, the Chief Information officer (CIO) has decided to review and update the company's privacy...
security awarenessprivacy policyrole-based trainingprogram design - Question #133Enterprise Security
The Chief Information Officer (CIO) of a technology company is likely to move away from a de- perimeterized model for employee owned devices. This is because there were too many is...
BYODendpoint securityde-perimeterizationmobile device management - Question #134Technical Integration of Enterprise Components
A financial institution wants to reduce the costs associated with managing and troubleshooting employees' desktops and applications, while keeping employees from copying data onto...
VDIdesktop virtualizationdata loss preventionthin client - Question #135Integration of Computing, Communications and Business Disciplines
A security engineer is implementing a new solution designed to process e-business transactions and record them in a corporate audit database. The project has multiple technical sta...
solution ownershipe-business securitystakeholder managementaudit trail - Question #136Enterprise Security
A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which...
risk managementplan of action and milestonesvulnerability assessmentcontinuous monitoring - Question #137Enterprise Security
An administrator is notified that contract workers will be onsite assisting with a new project. The administrator wants each worker to be aware of the corporate policy pertaining t...
USB storage policycontractor agreementsbusiness partnership agreementacceptable use - Question #138Technical Integration of Enterprise Components
The VoIP administrator starts receiving reports that users are having problems placing phone calls. The VoIP administrator cannot determine the issue, and asks the security adminis...
VoIP securitySIP flooddenial of servicerate limiting - Question #139Enterprise Security
A Chief Information Security Officer (CISO) of a major consulting firm has significantly increased the company's security posture; however, the company is still plagued by data bre...
full disk encryptiondata breachasset managementendpoint security - Question #140Technical Integration of Enterprise Components
A security administrator must implement a SCADA style network overlay to ensure secure remote management of all network management and infrastructure devices. Which of the followin...
SCADAout-of-band managementnetwork segmentationinfrastructure security - Question #141Technical Integration of Enterprise Components
An IT administrator wants to restrict DNS zone transfers between two geographically dispersed, external company DNS name servers, and has decided to use TSIG. Which of the followin...
TSIGDNS zone transferkey managementNTP synchronization - Question #142Enterprise Security
A company receives an e-discovery request for the Chief Information Officer's (CIO's) email data. The storage administrator reports that the data retention policy relevant to their...
e-discoverydata retentionlegal complianceemail archiving - Question #143Integration of Computing, Communications and Business Disciplines
A team is established to create a secure connection between software packages in order to list employee's remaining or unused benefits on their paycheck stubs. Which of the followi...
cross-functional teamHR integrationpayroll securityrole assignment - Question #144Technical Integration of Enterprise Components
A WAF without customization will protect the infrastructure from which of the following attack combinations?
WAFSQL injectionXSSHTTP exhaustion - Question #145Enterprise Security
Company XYZ has transferred all of the corporate servers, including web servers, to a cloud hosting provider to reduce costs. All of the servers are running unpatched, outdated ver...
cloud securitypatch managementrisk prioritizationApache vulnerabilities - Question #146Technical Integration of Enterprise Components
A hosting company provides inexpensive guest virtual machines to low-margin customers. Customers manage their own guest virtual machines. Some customers want basic guarantees of lo...
VM isolationhypervisor firewallcloud hostinglogical separation - Question #147Integration of Computing, Communications and Business Disciplines
An organization has had component integration related vulnerabilities exploited in consecutive releases of the software it hosts. The only reason the company was able to identify t...
SDLCcomponent integrationcross-functional testingcode review - Question #148Enterprise Security
New zero-day attacks are announced on a regular basis against a broad range of technology systems. Which of the following best practices should a security manager do to manage the...
zero-day attacksapplication inventorycritical systemsrisk management - Question #149Technical Integration of Enterprise Components
A financial company implements end-to-end encryption via SSL in the DMZ, and only IPSec in transport mode with AH enabled and ESP disabled throughout the internal network. The comp...
IPSec AH/ESP modesNIPS/HIPS placementSSL/TLS DMZnetwork security architecture - Question #150Integration of Computing, Communications and Business Disciplines
An administrator at a small company replaces servers whenever budget money becomes available. Over the past several years the company has acquired and still uses 20 servers and 50...
technology lifecycle managementpatch managementlegacy hardwareOS end-of-support - Question #151Enterprise Security
A security administrator wants to verify and improve the security of a business process which is tied to proven company workflow. The security administrator was able to improve sec...
gap analysisnon-technical controlssecurity standardsresidual risk - Question #152Integration of Computing, Communications and Business Disciplines
About twice a year a switch fails in a company's network center. Under the maintenance contract, the switch would be replaced in two hours losing the business $1,000 per hour. The...
cost-benefit analysisdowntime costsmaintenance contractsrisk management