CAS-002 Exam Questions
884 real CAS-002 exam questions with expert-verified answers and explanations. Page 5 of 18.
- Question #206Research and Analysis
-- Exhibit Company management has indicated that instant messengers (IM) add to employee productivity. Management would like to implement an IM solution, but does not have a budget...
instant messaging securitysecurity feature analysisproduct evaluationfeature matrix - Question #207Integration of Computing, Communications and Business Disciplines
Company ABC will test connecting networks with Company XYZ as part of their upcoming merger and are both concerned with minimizing security exposures to each others network through...
network integrationdata flow analysismerger securitynetwork connectivity - Question #208Research and Analysis
Which of the following activities is commonly deemed "OUT OF SCOPE" when undertaking a penetration test?
penetration testingscope definitionDoS attacksrules of engagement - Question #209Enterprise Security
Company XYZ provides hosting services for hundreds of companies across multiple industries including healthcare, education, and manufacturing. The security architect for company XY...
multi-tenant virtualizationdata separationPII compliancecloud hosting liability - Question #210Technical Integration of Enterprise Components
Which of the following protocols only facilitates access control?
XACMLaccess controlauthorization protocolsSAML vs SPML - Question #211Enterprise Security
A security auditor is conducting an audit of a corporation where 95% of the users travel or work from non-corporate locations a majority of the time. While the employees are away f...
full disk encryptionmobile workforcePII protectiondata at rest - Question #212Technical Integration of Enterprise Components
A general insurance company wants to set up a new online business. The requirements are that the solution needs to be: Extendable for new products to be developed and added Externa...
WS-SecurityXACMLSSL/TLSservice-oriented architecture - Question #213Integration of Computing, Communications and Business Disciplines
An external auditor has found that IT security policies in the organization are not maintained and in some cases are nonexistent. As a result of the audit findings, the CISO has be...
eGRCpolicy lifecycle managementgovernance frameworksCISO responsibilities - Question #214Technical Integration of Enterprise Components
Company A needs to export sensitive data from its financial system to company B's database, using company B's API in an automated manner. Company A's policy prohibits the use of an...
SSL tunnelingdata in transit encryptionlegacy system integrationend-to-end encryption - Question #215Technical Integration of Enterprise Components
Two storage administrators are discussing which SAN configurations will offer the MOST confidentiality. Which of the following configurations would the administrators use? (Select...
SAN securityLUN maskingzoningstorage confidentiality - Question #216Enterprise Security
The Information Security Officer (ISO) believes that the company has been targeted by cybercriminals and it is under a cyber attack. Internal services that are normally available t...
DDoSamplification attacknetwork forensicsincident response - Question #217Integration of Computing, Communications and Business Disciplines
The Information Security Officer (ISO) is reviewing new policies that have been recently made effective and now apply to the company. Upon review, the ISO identifies a new requirem...
policy exceptionrisk acceptancecompensating controlstwo-factor authentication - Question #218Research and Analysis
A government agency considers confidentiality to be of utmost importance and availability issues to be of least importance. Knowing this, which of the following correctly orders va...
vulnerability prioritizationCIA triadconfidentialityrisk ranking - Question #219Integration of Computing, Communications and Business Disciplines
A security policy states that all applications on the network must have a password length of eight characters. There are three legacy applications on the network that cannot meet t...
risk exceptionlegacy systemspassword policyrisk management - Question #220Technical Integration of Enterprise Components
A retail bank has had a number of issues in regards to the integrity of sensitive information across all of its customer databases. This has resulted in the bank's share price decr...
SIEMlog aggregationsecurity operations centeraudit logging - Question #221Enterprise Security
A security engineer is troubleshooting a possible virus infection, which may have spread to multiple desktop computers within the organization. The company implements enterprise an...
malware detectioncloud security servicesbotnet indicatorsAV evasion - Question #222Technical Integration of Enterprise Components
Company XYZ provides cable television service to several regional areas. They are currently installing fiber-to-the-home in many areas with hopes of also providing telephone and In...
federated identityIdPservice providerSSO - Question #223Technical Integration of Enterprise Components
After being informed that the company DNS is unresponsive, the system administrator issues the following command from a Linux workstation: - SSH-p 2020-l user dnsserver.company.com...
Linux privilegessudoDNS administrationleast privilege - Question #224Integration of Computing, Communications and Business Disciplines
An administrator receives a notification from legal that an investigation is being performed on members of the finance department. As a precaution, legal has advised a legal hold o...
legal holddata retention policydata storage policye-discovery - Question #225Research and Analysis
A vulnerability research team has detected a new variant of a stealth Trojan that disables itself when it detects that it is running on a virtualized environment. The team decides...
malware analysispacket captureanti-VM Trojannetwork forensics - Question #226Integration of Computing, Communications and Business Disciplines
The Information Security Officer (ISO) is reviewing a summary of the findings from the last COOP tabletop exercise. The Chief Information Officer (CIO) wants to determine which add...
COOPtabletop exerciseVoIP availabilitybusiness continuity - Question #227Enterprise Security
A corporation implements a mobile device policy on smartphones that utilizes a white list for allowed applications. Recently, the security administrator notices that a consumer clo...
mobile device managementcloud storagedata exfiltrationapplication whitelist - Question #228Technical Integration of Enterprise Components
A trust relationship has been established between two organizations with web based services. One organization is acting as the Requesting Authority (RA) and the other acts as the P...
SPMLSAMLSOAPprovisioning trust relationships - Question #229Technical Integration of Enterprise Components
A Linux security administrator is attempting to resolve performance issues with new software installed on several baselined user systems. After investigating, the security administ...
SELinuxmandatory access controlenforcing modetrusted operating system - Question #230Enterprise Security
Which of the following does SAML uses to prevent government auditors or law enforcement from identifying specific entities as having already connected to a service provider through...
SAMLtransient identifiersSSO privacyidentity federation - Question #231Enterprise Security
In order to reduce costs and improve employee satisfaction, a large corporation is creating a BYOD policy. It will allow access to email and remote connections to the corporate ent...
BYODNACdata encryptionmobile security - Question #232Enterprise Security
Which of the following are components defined within an Enterprise Security Architecture Framework? (Select THREE).
security architecture frameworkreference modelsbusiness capabilitiesenterprise drivers - Question #233Integration of Computing, Communications and Business Disciplines
The organization has an IT driver on cloud computing to improve delivery times for IT solution provisioning. Separate to this initiative, a business case has been approved for repl...
cloud computingPCI DSSregulatory compliancerisk assessment - Question #234Technical Integration of Enterprise Components
A security administrator is tasked with securing a company's headquarters and branch offices move to unified communications. The Chief Information Officer (CIO) wants to integrate...
unified communicationsSIPsecure RTPpresence management - Question #235Enterprise Security
A security code reviewer has been engaged to manually review a legacy application. A number of systemic issues have been uncovered relating to buffer overflows and format string vu...
managed codebuffer overflowsecure codinglanguage selection - Question #236Technical Integration of Enterprise Components
A large enterprise introduced a next generation firewall appliance into the Internet facing DMZ. All Internet traffic passes through this appliance. Four hours after implementation...
firewall implementationperformance testingDMZnetwork engineering - Question #237Technical Integration of Enterprise Components
A security administrator is tasked with implementing two-factor authentication for the company VPN. The VPN is currently configured to authenticate VPN users against a backend RADI...
PKIVPNRADIUScertificate management - Question #238Enterprise Security
Part of the procedure for decommissioning a database server is to wipe all local disks, as well as SAN LUNs allocated to the server, even though the SAN itself is not being decommi...
data remanenceSANdecommissioningdata sanitization - Question #239Technical Integration of Enterprise Components
At 9:00 am each morning, all of the virtual desktops in a VDI implementation become extremely slow and/or unresponsive. The outage lasts for around 10 minutes, after which everythi...
VDI boot stormI/O performancestorage optimizationSSD - Question #240Integration of Computing, Communications and Business Disciplines
The Chief Executive Officer (CEO) of a large prestigious enterprise has decided to reduce business costs by outsourcing to a third party company in another country. Functions to be...
outsourcing riskdata privacyintellectual propertyregulatory compliance - Question #241Enterprise Security
A developer has implemented a piece of client-side JavaScript code to sanitize a user's provided input to a web page login screen. The code ensures that only the upper case and low...
SQL injectionclient-side validationinput sanitizationweb application security - Question #242Enterprise Security
In developing a new computing lifecycle process for a large corporation, the security team is developing the process for decommissioning computing equipment. In order to reduce the...
data destructiondrive sanitizationdecommissioningdata leakage prevention - Question #243Integration of Computing, Communications and Business Disciplines
The Universal Research Association has just been acquired by the Association of Medical Business Researchers. The new conglomerate has funds to upgrade or replace hardware as part...
M&A integrationregulatory complianceIT standardsinteroperability - Question #244Enterprise Security
The senior security administrator wants to redesign the company DMZ to minimize the risks associated with both external and internal threats. The DMZ design must support security i...
DMZ designdefense in depthdual firewallincident reconstruction - Question #245Enterprise Security
A large bank deployed a DLP solution to detect and block customer and credit card data from leaving the organization via email. A disgruntled employee was able to successfully exfi...
DLPdata exfiltrationobject embeddingcontent inspection - Question #246Technical Integration of Enterprise Components
The security administrator of a large enterprise is tasked with installing and configuring a solution that will allow the company to inspect HTTPS traffic for signs of hidden malwa...
HTTPS inspectionSSL/TLS proxycertificate authoritypolicy-based routing - Question #247Technical Integration of Enterprise Components
A bank provides single sign on services between its internally hosted applications and externally hosted CRM. The following sequence of events occurs: 1. The banker accesses the CR...
SAML 2.0SSOfederated identityservice provider - Question #248Technical Integration of Enterprise Components
An administrator attempts to install the package "named.9.3.6-12-x86_64.rpm" on a server. Even though the package was downloaded from the official repository, the server states the...
GPGpackage signingsoftware integrityLinux administration - Question #249Research and Analysis
The Chief Information Security Officer (CISO) at a software development company is concerned about the lack of introspection during a testing cycle of the company's flagship produc...
white box testingcode coveragesoftware testing methodologysecurity testing - Question #250Technical Integration of Enterprise Components
A security architect is designing a new infrastructure using both type 1 and type 2 virtual machines. In addition to the normal complement of security controls (e.g. antivirus, hos...
vTPMvirtualization securitycryptographic key storagehypervisor - Question #251Integration of Computing, Communications and Business Disciplines
A company has implemented data retention policies and storage quotas in response to their legal department's requests and the SAN administrator's recommendation. The retention poli...
e-discoverydata retentionlegal holdscompliance - Question #252Enterprise Security
A new internal network segmentation solution will be implemented into the enterprise that consists of 200 internal firewalls. As part of running a pilot exercise, it was determined...
network segmentationfirewall managementcontrol effectivenessrisk assessment - Question #253Technical Integration of Enterprise Components
Three companies want to allow their employees to seamlessly connect to each other's wireless corporate networks while keeping one consistent wireless client configuration. Each com...
802.1xRADIUS federationEAP-PEAPwireless authentication - Question #254Enterprise Security
Which of the following BEST explains SAML?
SAMLSSOXMLfederated identity - Question #255Research and Analysis
An Association is preparing to upgrade their firewalls at five locations around the United States. Each of the three vendor's RFP responses is in-line with the security and other r...
vendor evaluationfirewalllab testingRFP