CAS-003 Exam Questions
947 real CAS-003 exam questions with expert-verified answers and explanations. Page 12 of 19.
- Question #564Risk Management
A regional transportation and logistics company recently hired its first Chief Information Security Officer (CISO). The CISO's first project after onboarding involved performing a...
legacy systemsWAFvulnerability managementcompensating controls - Question #565Risk Management
Ann, a retiring employee, cleaned out her desk. The next day, Ann's manager notices company equipment that was supposed to remain at her desk is now missing. Which of the following...
employee separationasset managementoffboardingHR security - Question #566Enterprise Security Operations
A security analyst for a bank received an anonymous tip on the external banking website showing the following: Protocols supported - TLS 1.0 - SSL 3 - SSL 2 Cipher suites supported...
SSL/TLS analysiscipher suitesPOODLEvulnerability assessment - Question #567Technical Integration of Enterprise Security
A company is moving all of its web applications to an SSO configuration using SAML. Some employees report that when signing in to an application, they get an error message on the l...
SSOSAMLfederationauthentication troubleshooting - Question #568Enterprise Security Operations
A penetration tester is trying to gain access to a remote system. The tester is able to see the secure login page and knows one user account and email address, but has not yet disc...
social engineeringpenetration testingcredential attackspassword acquisition - Question #569Enterprise Security Operations
A technician is reviewing the following log: Which of the following tools should the organization implement to reduce the highest risk identified in this log?
DLPlog analysisdata loss preventionsecurity tooling - Question #570Risk Management
A Chief Information Security Officer (CISO) is creating a security committee involving multiple business units of the corporation. Which of the following is the BEST justification...
security governancebusiness unit collaborationrisk ownershipsecurity committee - Question #571Enterprise Security Architecture
Due to a recent acquisition, the security team must find a way to secure several legacy applications. During a review of the applications, the following issues are documented: - Th...
legacy application securitynetwork segmentationPII/PHITLS hardening - Question #572Technical Integration of Enterprise Security
A new security policy states all wireless and wired authentication must include the use of certificates when connecting to internal resources within the enterprise LAN by all emplo...
802.1XPKIcertificate-based authenticationnetwork access control - Question #573Enterprise Security Operations
A security consultant was hired to audit a company's password are account policy. The company implements the following controls: - Minimum password length: 16 - Maximum password ag...
password sprayingPBKDF2account lockout policyoffline vs online attacks - Question #574Risk Management
As part of the asset management life cycle, a company engages a certified equipment disposal vendor to appropriately recycle and destroy company assets that are no longer in use. A...
vendor due diligenceasset disposalthird-party riskcompliance certification - Question #575Enterprise Security Operations
Following a complete outage of the electronic medical record system for more than 18 hours, the hospital's Chief Executive Officer (CEO) has requested that the Chief Information Se...
configuration managementchange managementaudit logsnetwork devices - Question #576Technical Integration of Enterprise Security
A company's user community is being adversely affected by various types of emails whose authenticity cannot be trusted. The Chief Information Security Officer (CISO) must address t...
DMARCspam filteringemail authenticationphishing defense - Question #577Enterprise Security Operations
The audit team was only provided the physical and logical addresses of the network without any type of access credentials. Which of the following methods should the audit team use...
penetration testingsocial engineeringblack-box assessmentinitial access - Question #578Risk Management
A product manager is concerned about the unintentional sharing of the company's intellectual property through employees' use of social media. Which of the following would BEST miti...
web content filteringdata loss preventionintellectual propertysocial media risk - Question #579Enterprise Security Architecture
An organization is evaluating options related to moving organizational assets to a cloud-based environment using an IaaS provider. One engineer has suggested connecting a second cl...
cloud deployment modelshybrid cloudIaaShosted private cloud - Question #580Technical Integration of Enterprise Security
A company uses an application in its warehouse that works with several commercially available tablets and can only be accessed inside the warehouse. The support department would li...
COPEgeofencingMDMmobile device management - Question #581Risk Management
During a recent incident, sensitive data was disclosed and subsequently destroyed through a properly secured, cloud-based storage platform. An incident response technician is worki...
breach impactregulatory exposureincident metricssenior leadership communication - Question #582Enterprise Security Operations
After an employee was terminated, the company discovered the employee still had access to emails and attached content that should have been destroyed during the off-boarding. The e...
off-boarding controlsaccess managementinsider threatgeographic restrictions - Question #583Enterprise Security Operations
A newly hired Chief Information Security Officer (CISO) wants to understand how the organization's CIRT handles issues brought to their attention, but needs to be very cautious abo...
tabletop exerciseCIRT assessmentincident responsenon-disruptive testing - Question #584Technical Integration of Enterprise Security
A systems analyst is concerned that the current authentication system may not provide the appropriate level of security. The company has integrated WAYF within its federation syste...
TOTPcredential replayphishing resistancefederation WAYF - Question #585Enterprise Security Architecture
A security architect has designated that a server segment of an enterprise network will require each server to have secure and measured boot capabilities. The architect now wishes...
measured bootremote attestationHSMsupply chain integrity - Question #587Enterprise Security Operations
A company recently experienced a security incident in which its domain controllers were the target of a DoS attack. In which of the following steps should technicians connect domai...
incident response phasesrecoveryDoS attackdomain controller - Question #588Enterprise Security Operations
A company uses an enterprise desktop imaging solution to manage deployment of its desktop computers. Desktop computer users are only permitted to use software that is part of the b...
application whitelistingendpoint hardeningsoftware controldesktop security - Question #589Risk Management
A government contracting company issues smartphones to employees to enable access to corporate resources. Several employees will need to travel to a foreign country for business pu...
MDMinternational travel risklocation servicesmobile threat defense - Question #590Risk Management
A Chief Information Security Officer (CISO) needs to create a policy set that meets international standards for data privacy and sharing. Which of the following should the CISO rea...
GDPRdata privacyinternational complianceregulatory frameworks - Question #591Technical Integration of Enterprise Security
A financial institution would like to store its customer data in a cloud but still allow the data to be accessed and manipulated while encrypted. Doing so would prevent the cloud s...
homomorphic encryptioncloud data privacycryptographic techniquesencrypted computation - Question #592Technical Integration of Enterprise Security
A smart switch has the ability to monitor electrical levels and shut off power to a building in the event of power surge or other fault situation. The switch was installed on a wir...
IoT hardeningdefault credentialssmart device securityOT/ICS security - Question #593Enterprise Security Operations
Which of the following attacks can be used to exploit a vulnerability that was created by untrained users?
spear-phishingsocial engineeringuser awareness trainingphishing vectors - Question #594Enterprise Security Operations
An organization is struggling to differentiate threats from normal traffic and access to systems. A security engineer has been asked to recommend a system that will aggregate data...
SIEMlog aggregationanomaly detectionthreat detection - Question #595Risk Management
Which of the following attacks can be mitigated by proper data retention policies?
dumpster divingdata retentiondata disposalphysical security - Question #596Risk Management
Which of the following may indicate a configuration item has reached end-of-life?
end-of-lifepatch managementvendor supportasset lifecycle - Question #597Enterprise Security Operations
The SOC is reviewing processes and procedures after a recent incident. The review indicates it took more than 30 minutes to determine that quarantining an infected host was the bes...
incident responseplaybookmalware containmentSOC process - Question #598Enterprise Security Architecture
A large industrial system's smart generator monitors the system status and sends alerts to third- party maintenance personnel when critical failures occur. While reviewing the netw...
network segmentationIoT securityOT/ICS securitynetwork architecture - Question #599Technical Integration of Enterprise Security
Which of the following are the MOST likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two.)
supply chainthird-party librariesSDLCsoftware vulnerabilities - Question #600Enterprise Security Architecture
A security manager needed to protect a high-security data center, so the manager installed a mantrap that can detect an employee's heartbeat, weight, and badge. Which of the follow...
physical securitymantrapbiometric access controlsecurity control types - Question #601Enterprise Security Operations
An organization is concerned that its hosted web servers are not running the most updated version of software. Which of the following would work BEST to help identify potential vul...
nmapversion detectionvulnerability scanningnetwork reconnaissance - Question #602Enterprise Security Architecture
A security administrator adding a NAC requirement for all VPN users to ensure the connecting devices are compliant with company policy. Which of the following items provides the HI...
NACPKIVPN compliancedevice assurance - Question #603Technical Integration of Enterprise Security
A company wants to configure its wireless network to require username and password authentication. Which of the following should the system administrator implement?
wireless securityPEAP802.1Xauthentication protocols - Question #604Enterprise Security Operations
Ann, a security manager, is reviewing a threat feed that provides information about attacks that allow a malicious user to gain access to private contact lists. Ann receives a noti...
threat intelligencevulnerability exploitationsocial engineeringcontact list exposure - Question #605Enterprise Security Operations
A security analyst is reviewing the following pseudo-output snippet after running the command /tmp/file.tmp. less The information above was obtained from a public-facing website an...
geotaggingmetadata sanitizationOSINTdata leakage - Question #606Technical Integration of Enterprise Security
A remote user reports the inability to authenticate to the VPN concentrator. During troubleshooting, a security administrate captures an attempted authentication and discovers the...
PKIdigital certificatescertificate revocationVPN authentication - Question #607Technical Integration of Enterprise Security
A DevOps team wants to move production data into the QA environment for testing. This data contains credit card numbers and expiration dates that are not tied to any individuals. T...
data maskingtokenizationPCI data protectiontest environment security - Question #608Enterprise Security Operations
Following the most recent patch deployment, a security engineer receives reports that the ERP application is no longer accessible. The security engineer reviews the situation and d...
patch managementHIPScompensating controlsvulnerability management - Question #609Risk Management
A Chief Information Security Officer (CISO) is running a test to evaluate the security of the corporate network and attached devices. Which of the following components should be ex...
penetration testingthird-party assessmentindependent verificationsecurity testing - Question #610Risk Management
A security manager is determining the best DLP solution for an enterprise. A list of requirements was created to use during the source selection. The security manager wants to conf...
RFIDLPvendor selectionprocurement process - Question #611Risk Management
Designing a system in which only information that is essential for a particular job task is allowed to be viewed can be accomplished successfully by using:
RBACleast privilegeneed-to-knowaccess control - Question #612Risk Management
The information security manager of an e-commerce company receives an alert over the weekend that all the servers in a datacenter have gone offline. Upon discussing this situation...
change managementbusiness continuityavailabilityBCP - Question #613Enterprise Security Operations
A company contracts a security consultant to perform a remote white-box penetration test. The company wants the consultant to focus on Internet-facing services without negatively i...
penetration testingreconnaissanceattack surfaceWHOIS - Question #614Enterprise Security Operations
A company is concerned about disgruntled employees transferring its intellectual property data through covert channels. Which of the following tools would allow employees to write...
covert channelsICMP tunnelingdata exfiltrationLoki