CAS-002 Exam Questions
884 real CAS-002 exam questions with expert-verified answers and explanations. Page 6 of 18.
- Question #256Enterprise Security
When generating a new key pair, a security application asks the user to move the mouse and type random characters on the keyboard. Which of the following BEST describes why this is...
entropykey generationcryptographyrandomness - Question #257Enterprise Security
Ann, a software developer, wants to publish her newly developed software to an online store. Ann wants to ensure that the software will not be modified by a third party or end user...
remote attestationcode signingmobile securitysoftware integrity - Question #258Enterprise Security
During a new desktop refresh, all hosts are hardened at the OS level before deployment to comply with policy. Six months later, the company is audited for compliance to regulations...
compliance driftconfiguration managementOS hardeningaudit - Question #259Integration of Computing, Communications and Business Disciplines
A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have ag...
mergers and acquisitionsregulatory complianceIT integrationoperational procedures - Question #260Technical Integration of Enterprise Components
Company XYZ has just purchased Company ABC through a new acquisition. A business decision has been made to integrate the two company's networks, application, and several basic serv...
network integrationfirewall placementtrust boundariesacquisition - Question #261Technical Integration of Enterprise Components
Company ABC's SAN is nearing capacity, and will cause costly downtimes if servers run out disk space. Which of the following is a more cost effective alternative to buying a new SA...
SAN managementdeduplicationstorage optimizationcost efficiency - Question #262Enterprise Security
A sensitive database needs its cryptographic integrity upheld. Which of the following controls meets this goal? (Select TWO).
data integritydata signingRBACcryptographic controls - Question #263Enterprise Security
The security administrator finds unauthorized tables and records, which were not present before, on a Linux database server. The database server communicates only with one web serv...
SQL injectionprivilege escalationweb server logsdirectory traversal - Question #264Technical Integration of Enterprise Components
An administrator has four virtual guests on a host server. Two of the servers are corporate SQL servers, one is a corporate mail server, and one is a testing web server for a small...
virtualizationout-of-band managementdedicated NICvirtual switch - Question #265Technical Integration of Enterprise Components
Warehouse users are reporting performance issues at the end of each month when trying to access cloud applications to complete their end of the month financial reports. They have n...
traffic shapingQoSbandwidth managementnetwork performance - Question #266Technical Integration of Enterprise Components
Ann, a Physical Security Manager, is ready to replace all 50 analog surveillance cameras with IP cameras with built-in web management. Ann has several security guard desks on diffe...
IP camera securityauthentication proxynetwork segmentationphysical security - Question #267Enterprise Security
An organization has just released a new mobile application for its customers. The application has an inbuilt browser and native application to render content from existing websites...
SSOmobile securitytoken storageauthentication - Question #268Enterprise Security
An audit at a popular on-line shopping site reveals that a flaw in the website allows customers to purchase goods at a discounted rate. To improve security the Chief Information Se...
input validationfuzzingHTTP interceptorweb application security - Question #269Research and Analysis
A security administrator at Company XYZ is trying to develop a body of knowledge to enable heuristic and behavior based security event monitoring of activities on a geographically...
security baselineheuristic monitoringnetwork modelingbehavioral analysis - Question #270Enterprise Security
A Security Manager is part of a team selecting web conferencing systems for internal use. The system will only be used for internal employee collaboration. Which of the following a...
web conferencingdata storage securityavailabilityuser authentication - Question #271Technical Integration of Enterprise Components
A system administrator has installed a new Internet facing secure web application that consists of a Linux web server and Windows SQL server into a new corporate site. The administ...
DMZnetwork segmentationfirewall zonesweb server security - Question #272Enterprise Security
Company XYZ plans to donate 1,000 used computers to a local school. The company has a large research and development section and some of the computers were previously used to store...
data sanitizationasset disposaldata handling policydata remnants - Question #273Enterprise Security
Which of the following is an example of single sign-on?
SSOweb access controlattribute passingauthentication - Question #274Enterprise Security
Which of the following BEST describes the implications of placing an IDS device inside or outside of the corporate firewall?
IDS placementfirewallintrusion detectionnetwork monitoring - Question #275Integration of Computing, Communications and Business Disciplines
Company XYZ has employed a consultant to perform a controls assessment of the HR system, backend business operations, and the SCADA system used in the factory. Which of the followi...
risk managementrisk treatmentcontrols assessmentSCADA - Question #276Integration of Computing, Communications and Business Disciplines
The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function wi...
risk transferBIArisk treatmentbudget constraints - Question #277Enterprise Security
Some mobile devices are jail-broken by connecting via USB cable and then exploiting software vulnerabilities to get kernel-level access. Which of the following attack types represe...
mobile securityprivilege escalationphysical attackjailbreaking - Question #278Integration of Computing, Communications and Business Disciplines
The Chief Information Security Officer (CISO) regularly receives reports of a single department repeatedly violating the corporate security policy. The head of the department in qu...
security policyMOUgovernancebusiness alignment - Question #279Technical Integration of Enterprise Components
A university Chief Information Security Officer is analyzing various solutions for a new project involving the upgrade of the network infrastructure within the campus. The campus h...
WLANnetwork designrisk acceptancecampus network - Question #280Technical Integration of Enterprise Components
In a SPML exchange, which of the following BEST describes the three primary roles?
SPMLidentity provisioningdirectory servicesIAM - Question #281Technical Integration of Enterprise Components
The security administrator has just installed an active\passive cluster of two firewalls for enterprise perimeter defense of the corporate network. Stateful firewall inspection is...
stateful firewallHA clustersession stateperimeter defense - Question #282Enterprise Security
Which of the following types of attacks is the user attempting? select id, firstname, lastname from authors User input= firstname= Hack;man lastname=Johnson
SQL injectionweb application attacksinput validation - Question #283Enterprise Security
Company XYZ has experienced a breach and has requested an internal investigation be conducted by the IT Department. Which of the following represents the correct order of the inves...
digital forensicsincident responsechain of custodyevidence handling - Question #284Enterprise Security
A system administrator has a responsibility to maintain the security of the video teleconferencing system. During a self-audit of the video teleconferencing room, the administrator...
Bluetooth securityphysical securitywirelessRF emanation - Question #285Research and Analysis
A large organization that builds and configures every data center against distinct requirements loses efficiency, which results in slow response time to resolve issues. However, to...
vendor diversitysingle point of failurerisk concentrationenterprise architecture - Question #286Enterprise Security
A security engineer at a software development company has identified several vulnerabilities in a product late in the development cycle. This causes a huge delay for the release of...
SDLCagile developmentsecure codingsoftware security - Question #287Integration of Computing, Communications and Business Disciplines
The manager of the firewall team is getting complaints from various IT teams that firewall changes are causing issues. Which of the following should the manager recommend to BEST a...
change managementfirewall managementIT governancecommunication - Question #288Research and Analysis
An asset manager is struggling with the best way to reduce the time required to perform asset location activities in a large warehouse. A project manager indicated that RFID might...
RFIDasset managementwireless securitydata encryption - Question #289Technical Integration of Enterprise Components
An organization is selecting a SaaS provider to replace its legacy, in house Customer Resource Management (CRM) application. Which of the following ensures the organization mitigat...
SaaS securityfederationSSOidentity management - Question #290Integration of Computing, Communications and Business Disciplines
The Chief Information Officer (CIO) is focused on improving IT governance within the organization to reduce system downtime. The CIO has mandated that the following improvements be...
IT governancechange managementrisk managementITIL - Question #292Enterprise Security
A security architect is locked into a given cryptographic design based on the allowable software at the company. The key length for applications is already fixed as is the cipher a...
entropycryptographykey managementbrute force mitigation - Question #293Integration of Computing, Communications and Business Disciplines
The Chief Risk Officer (CRO) has requested that the MTD, RTO and RPO for key business applications be identified and documented. Which of the following business documents would MOS...
BIARTORPOMTD - Question #294Enterprise Security
A security administrator is investigating the compromise of a SCADA network that is not physically connected to any other network. Which of the following is the MOST likely cause o...
SCADA securityair-gapped networkUSB threatICS security - Question #295Research and Analysis
A company uses a custom Line of Business (LOB) application to facilitate all back-end manufacturing control. Upon investigation, it has been determined that the database used by th...
vendor lock-inproprietary formatdata portabilityoperational risk - Question #296Technical Integration of Enterprise Components
A security engineer has inherited an authentication project which integrates 1024-bit PKI certificates into the company infrastructure and now has a new requirement to integrate 20...
PKIcertificate managementcryptographic migrationproject management - Question #297Enterprise Security
A security engineer wants to implement forward secrecy but still wants to ensure the number of requests handled by the web server is not drastically reduced due to the larger compu...
forward secrecyECDHEkey exchange performanceTLS - Question #298Integration of Computing, Communications and Business Disciplines
An organization is finalizing a contract with a managed security services provider (MSSP) that is responsible for primary support of all security technologies. Which of the followi...
MSSP contractsinterconnection security agreementthird-party securityvendor management - Question #299Integration of Computing, Communications and Business Disciplines
For companies seeking to move to cloud services, variances in regulation between jurisdictions can be addressed in which of the following ways?
data sovereigntycloud compliancegeographic restrictionsVM tagging - Question #300Integration of Computing, Communications and Business Disciplines
A software development manager is taking over an existing software development project. The team currently suffers from poor communication, and this gap is resulting in an above av...
Agile methodologySDLCdaily stand-upsecure development - Question #301Enterprise Security
A security officer is leading a lessons learned meeting. Which of the following should be components of that meeting? (Select TWO).
incident responselessons learnedpost-incident reviewfollow-up actions - Question #302Enterprise Security
A security consultant is investigating acts of corporate espionage within an organization. Each time the organization releases confidential information to high-ranking engineers, t...
digital watermarkinginsider threatdata leakagecorporate espionage - Question #303Technical Integration of Enterprise Components
A system administrator needs to meet the maximum amount of security goals for a new DNS infrastructure. The administrator deploys DNSSEC extensions to the domain names and infrastr...
DNSSECDNS securityauthenticationdata integrity - Question #304Technical Integration of Enterprise Components
The Chief Executive Officer (CEO) of an Internet service provider (ISP) has decided to limit the company's contribution to worldwide Distributed Denial of Service (DDoS) attacks. W...
DDoS mitigationingress filteringBCP38ISP security - Question #305Integration of Computing, Communications and Business Disciplines
A software development manager is taking over an existing software development project. The team currently suffers from poor communication due to a long delay between requirements...
waterfall methodologySDLCrequirements documentationsoftware development - Question #306Enterprise Security
The threat abatement program manager tasked the software engineer with identifying the fastest implementation of a hash function to protect passwords with the least number of colli...
password hashingSHA-512saltingcryptographic hash functions