CAS-003 Exam Questions
947 real CAS-003 exam questions with expert-verified answers and explanations. Page 11 of 19.
- Question #513Enterprise Security Architecture
A request has been approved for a vendor to access a new internal server using only HTTPS and SSH to manage the back-end system for the portal. Internal users just need HTTP and HT...
firewall rule orderingaccess control listsnetwork segmentationrule configuration - Question #514Research, Development and Collaboration
A firewall specialist has been newly assigned to participate in red team exercises and needs to ensure the skills represent real-world threats. Which of the following would be the...
red team researchsecurity conferencesbleeding-edge techniquesprofessional development - Question #515Risk Management
A company's Chief Operating Officer (COO) is concerned about the potential for competitors to infer proprietary information gathered from employees' social media accounts. Which of...
social media riskinsider threatOSINTdata leakage - Question #516Enterprise Security Architecture
An organization is implementing a virtualized thin-client solution for normal user computing and access. During a review of the architecture, concerns were raised that an attacker...
virtualization securitylateral movementthin client architectureVM isolation - Question #517Technical Integration of Enterprise Security
An online bank has contracted with a consultant to perform a security assessment of the bank's web portal. The consultant notices the login page is linked from the main page with H...
sslstripMITM attackHTTPS redirectTLS security - Question #518Technical Integration of Enterprise Security
A security administrator wants to implement controls to harden company-owned mobile devices. Company policy specifies the following requirements: - Mandatory access control must be...
SEAndroidmobile securitysecure bootMDM controls - Question #519Enterprise Security Architecture
While conducting online research about a company to prepare for an upcoming penetration test, a security analyst discovers detailed financial information on an investor website the...
full disk encryptionmobile device securitydata at restdata leakage prevention - Question #520Technical Integration of Enterprise Security
An organization wants to allow its employees to receive corporate email on their own smartphones. A security analyst is reviewing the following information contained within the fil...
BYODcontainerizationremote wipeMDM - Question #521Risk Management
An infrastructure team within an energy organization is at the end of a procurement process and has selected a vendor's SaaS platform to deliver services. As part of the legal nego...
SaaS risk managementrisk acceptancevendor managementdata residency - Question #522Enterprise Security Operations
A developer emails the following output to a security administrator for review: Which of the following tools might the security administrator use to perform further security assess...
HTTP interceptorweb application securitysecurity assessment toolstraffic analysis - Question #523Technical Integration of Enterprise Security
A software development company lost customers recently because of a large number of software issues. These issues were related to integrity and availability defects, including buff...
secure SDLCstatic analysiscontinuous integrationmemory safety - Question #524Technical Integration of Enterprise Security
An enterprise is trying to secure a specific web-based application by forcing the use of multifactor authentication. Currently, the enterprise cannot change the application's sign-...
SAML federationShibbolethmultifactor authenticationSSO - Question #525Technical Integration of Enterprise Security
After significant vulnerabilities and misconfigurations were found in numerous production web applications, a security manager identified the need to implement better development c...
input validationsecure error handlingweb application controlssecure SDLC - Question #526Research, Development and Collaboration
An organization wants to arm its cybersecurity defensive suite automatically with intelligence on zero-day threats shortly after they emerge. Acquiring tools and services that supp...
threat intelligence standardsCVEzero-day threatsSTIX/TAXII - Question #527Risk Management
A financial institution's information security officer is working with the risk management officer to determine what to do with the institution's residual risk after all security c...
residual riskrisk transferrisk tolerancerisk treatment strategies - Question #528Enterprise Security Operations
A large, public university has recently been experiencing an increase in ransomware attacks against computers connected to its network. Security engineers have discovered various s...
ransomware mitigationemail-borne threatsuser awareness trainingsocial engineering - Question #529Technical Integration of Enterprise Security
A security architect is reviewing the code for a company's financial website. The architect suggests adding the following HTML element, along with a server-side function, to genera...
CSRF preventionanti-forgery tokenweb application securitysecure coding - Question #531Enterprise Security Operations
Following a recent and very large corporate merger, the number of log files an SOC needs to review has approximately tripled. The Chief Information Security Officer (CISO) has not...
SIEM filteringlog managementSOC operationsalert noise reduction - Question #532Technical Integration of Enterprise Security
An organization is deploying IoT locks, sensors, and cameras, which operate over 802.11, to replace legacy building access control systems. These devices are capable of triggering...
IoT securitynetwork segmentationWPA2 EAPfirmware vulnerabilities - Question #533Risk Management
A security administrator is updating corporate policies to respond to an incident involving collusion between two systems administrators that went undetected for more than six mont...
separation of dutiesjob rotationinsider threatsecurity policy - Question #534Enterprise Security Architecture
A core router was manipulated by a credentialed bypass to send all network traffic through a secondary router under the control of an unauthorized user connected to the network by...
out-of-band managementrouter securitynetwork access control802.1X - Question #535Risk Management
An infrastructure team is at the end of a procurement process and has selected a vendor. As part of the final negotiation, there are a number of outstanding issues, including: 1. I...
vendor risk managementrisk acceptancedata sovereigntyprocurement security - Question #536Enterprise Security Architecture
A security analyst works for a defense contractor that produces classified research on drones. The contractor faces nearly constant attacks from sophisticated nation-state actors a...
defense in depthAPT defensedata confidentialitysecurity architecture - Question #537Enterprise Security Operations
A company recently implemented a variety of security services to detect various types of traffic that pose a threat to the company. The following services were enabled within the n...
user behavioral analyticsdata exfiltrationDLPsecurity monitoring - Question #538Enterprise Security Operations
An external red team member conducts a penetration test, attempting to gain physical access to a large organization's server room in a branch office. During reconnaissance, the red...
physical securitylock pickingpenetration testingred team - Question #539Risk Management
A company relies on an ICS to perform equipment monitoring functions that are federally mandated for operation of the facility. Fines for non-compliance could be costly. The ICS ha...
ICS securitylegacy systemsrisk transferrisk management - Question #540Technical Integration of Enterprise Security
During a sprint, developers are responsible for ensuring the expected outcome of a change is thoroughly evaluated for any security impacts. Any impacts must be reported to the team...
SDLC securityregression testingDevSecOpschange management - Question #541Risk Management
An organization is currently working with a client to migrate data between a legacy ERP system and a cloud-based ERP tool using a global PaaS provider. As part of the engagement, t...
data sanitizationdata sovereigntyregulatory compliancecloud migration - Question #542Enterprise Security Architecture
Which of the following is a feature of virtualization that can potentially create a single point of failure?
virtualizationserver consolidationsingle point of failureavailability - Question #543Enterprise Security Operations
A cybersecurity analyst has received an alert that well-known "call home" messages are continuously observed by network sensors at the network boundary. The proxy firewall successf...
command and controlmalwarenetwork monitoringtrue positive analysis - Question #544Enterprise Security Operations
A cybersecurity analyst is hired to review the security the posture of a company. The cybersecurity analyst notice a very high network bandwidth consumption due to SYN floods from...
SYN floodDDoS mitigationingress filteringincident response - Question #545Technical Integration of Enterprise Security
During a routine network scan, a security administrator discovered an unidentified service running on a new embedded and unmanaged HVAC controller, which is used to monitor the com...
SNMPv3IoT securityOT/ICS securitynetwork segmentation - Question #546Enterprise Security Operations
There have been several exploits to critical devices within the network. However, there is currently no process to perform vulnerability analysis. Which the following should the se...
vulnerability scanningvulnerability managementproduction environmentrisk prioritization - Question #547Technical Integration of Enterprise Security
Which of the following systems would be at the GREATEST risk of compromise if found to have an open vulnerability associated with perfect forward secrecy?
perfect forward secrecyVPN securitycryptographykey exchange - Question #548Enterprise Security Operations
An organization is attempting to harden its web servers and reduce the information that might be disclosed by potential attackers. A security analyst is reviewing vulnerability sca...
information disclosureweb server hardeningfile path exposurevulnerability remediation - Question #549Enterprise Security Operations
A technician receives the following security alert from the firewall's automated system: Evidence: host repeatedly visited a dynamic DNS domain (17 time) After reviewing the alert,...
dynamic DNSsecurity alert analysisC2 detectionfirewall logs - Question #550Enterprise Security Operations
A security analyst is reviewing logs and discovers that a company-owned computer issued to an employee is generating many alerts and warnings. The analyst continues to review the l...
red teamblue teamwhite teamsecurity exercise roles - Question #551Risk Management
A pharmacy gives its clients online access to their records and the ability to review bills and make payments. A new SSL vulnerability on a special platform was discovered, allowin...
SSL/TLS vulnerabilityPHIcardholder datadata classification - Question #552Enterprise Security Operations
The security configuration management policy states that all patches must undergo testing procedures before being moved into production. The security analyst notices a single web a...
patch managementsecurity policy complianceanomalous activityincident response - Question #553Enterprise Security Operations
A malware infection spread to numerous workstations within the marketing department. The workstations were quarantined and replaced with machines. Which of the following represents...
incident responsemalware eradicationworkstation remediationquarantine - Question #554Risk Management
A pharmacy gives its clients online access to their records and the ability to review bills and make payments. A new SSL vulnerability on a specific platform was discovered, allowi...
SSL/TLS vulnerabilitydata exposurePHIPCI DSS - Question #555Enterprise Security Operations
An analyst has noticed unusual activities in the SIEM to a .cn domain name. Which of the following should the analyst use to identify the content of the traffic?
SIEM analysisDNS trafficnetwork monitoringthreat investigation - Question #556Enterprise Security Architecture
The Chief Executive Officer (CEO) instructed the new Chief Information Security Officer (CISO) to provide a list of enhancements to the company's cybersecurity operation. As a resu...
NIST frameworksecurity standardsbest practicescompliance - Question #557Enterprise Security Operations
A cybersecurity analyst is conducting packet analysis on the following: Which of the following is occurring in the given packet capture?
ARP spoofingpacket analysisnetwork attacksMITM - Question #558Enterprise Security Architecture
An investigation showed a worm was introduced from an engineer's laptop. It was determined the company does not provide engineers with company-owned laptops, which would be subject...
BYOD securityHIDSmanagement networknetwork access control - Question #559Risk Management
A company recently implemented a new cloud storage solution and installed the required synchronization client on all company devices. A few months later, a breach of sensitive data...
mobile device securitycloud storagebiometric authenticationdata breach - Question #560Risk Management
A vendor develops a mobile application for global customers. The mobile application supports advanced encryption of data between the source (the mobile device) and the destination...
export controlsencryption compliancemobile applicationcryptography regulations - Question #561Technical Integration of Enterprise Security
A security engineer is working to secure an organization's VMs. While reviewing the workflow for creating VMs on demand, the engineer raises a concern about the integrity of the se...
virtualization securityvTPMsecure boothypervisor - Question #562Enterprise Security Operations
When implementing a penetration testing program, the Chief Information Security Officer (CISO) designates different organizational groups within the organization as having differen...
penetration testingwhite teamred teamrules of engagement - Question #563Enterprise Security Architecture
An enterprise's Chief Technology Officer (CTO) and Chief Information Security Officer (CISO) are meeting to discuss ongoing capacity and resource planning issues. The enterprise ha...
VM isolationresource sharingattack surfacevirtualization risk