CAS-003 Exam Questions
947 real CAS-003 exam questions with expert-verified answers and explanations. Page 13 of 19.
- Question #615Enterprise Security Architecture
A security engineer is making certain URLs from an internal application available on the Internet. The development team requires the following - The URLs are accessible only from i...
load balancingGeoIP restrictionsTLStraffic distribution - Question #616Technical Integration of Enterprise Security
A company enlists a trusted agent to implement a way to authenticate email senders positively. Which of the following is the BEST method for the company to prove Vie authenticity o...
email authenticationhardware tokensMFAnon-repudiation - Question #617Enterprise Security Operations
A company recently migrated to a SaaS-based email solution. The solution is configured as follows. - Passwords are synced to the cloud to allow for SSO - Cloud-based antivirus is e...
CASBSIEMcloud email securityvisibility - Question #618Enterprise Security Architecture
The Chief Information Security Officer (CISO) of a company that has highly sensitive corporate locations wants its security engineers to find a solution to growing concerns regardi...
MDMmobile containerizationgeofencingBYOD policy - Question #619Technical Integration of Enterprise Security
After analyzing code, two developers al a company bring these samples to the security operations manager. Which of the following would BEST solve these coding problems?
secure codingcredential managementhardcoded passwordsSDLC - Question #620Enterprise Security Operations
A security administrator receives reports that several workstations are unable to access resources within one network segment. A packet capture shows the segment is flooded with IC...
IPv6 securityICMPv6 floodingneighbor discoverynetwork attack - Question #621Technical Integration of Enterprise Security
Joe an application security engineer is performing an audit of an environmental control application. He has implemented a robust SDLC process and is reviewing API calls available t...
API securityauthenticationsecure channelSDLC - Question #622Enterprise Security Architecture
An organization implemented a secure boot on its most critical application servers which produce content and capability for other consuming servers A recent incident, however led t...
secure bootattestationTPMfirmware integrity - Question #623Enterprise Security Operations
A company's Internet connection is commonly saturated during business hours, affecting Internet availability. The company requires all Internet traffic to be business related. Afte...
SSL inspectionCDN traffictraffic analysisDLP - Question #624Enterprise Security Operations
An attacker has been compromising banking institution targets across a regional area. The Chief Information Security Officer (CISO) at a local bank wants to detect and prevent an a...
threat intelligenceIDSproactive defensesector sharing - Question #625Technical Integration of Enterprise Security
Users have reported that an internally developed web application is acting erratically, and the response output is inconsistent. The issue began after a web application dependency...
fuzzingapplication testingpatch managementregression testing - Question #626Risk Management
A company makes consumer health devices and needs to maintain strict confidentiality of unreleased product designs. Recently unauthorized photos of products still in development ha...
insider threatOSINTfitness device metadataphysical security - Question #627Risk Management
A manufacturing company's security engineer is concerned a remote actor may be able to access the ICS that is used to monitor the factory lines. The security engineer recently prop...
ICS securityvulnerability scanningattack surface reductionmetrics - Question #628Risk Management
A new corporate policy requires that all employees have access to corporate resources on personal mobile devices. The information assurance manager is concerned about the potential...
mobile device policycontainerizationdata protectionBYOD - Question #629Enterprise Security Architecture
A security consultant is conducting a penetration test against a customer enterprise local comprises local hosts and cloud-based servers. The hosting service employs a multitenancy...
cloud multitenancydata remnantsVM isolationcloud security - Question #630Enterprise Security Operations
A security administrator is concerned about employees connecting their personal devices to the company network. Doing so is against company policy. The network does not have a NAC...
device identificationARP tablesnetwork monitoringNAC - Question #631Technical Integration of Enterprise Security
An organization designs and develops safety-critical embedded firmware (inclusive of embedded OS and services) for the automotive industry. The organization has taken great care to...
embedded firmwareautomotive securityfirmware integrityOT security - Question #632Enterprise Security Operations
A consultant is planning an assessment of a customer-developed system. The system consists of a custom-engineered board with modified open-source drivers and a one- off management...
reverse engineeringhardware securitycustom system assessmentpenetration testing - Question #633Enterprise Security Operations
An organization's mobile device inventory recently provided notification that a zero-day vulnerability was identified in the code used to control the baseband of the devices. The d...
baseband vulnerabilityfirmware integrityMDMmobile device security - Question #634Enterprise Security Operations
Several recent ransomware outbreaks at a company have cost a significant amount of lost revenue. The security team needs to find a technical control mechanism that will meet the fo...
ransomware preventionHIPSbehavioral detectionendpoint security - Question #635Technical Integration of Enterprise Security
A technician uses an old SSL server due to budget constraints and discovers performance degrades dramatically after enabling PFS. The technician cannot determine why performance de...
Perfect Forward SecrecyRSA performanceSSL/TLScryptographic overhead - Question #636Enterprise Security Architecture
A company's human resources department recently had its own shadow IT department spin up ten VMs that host a mixture of differently labeled data types (confidential and restricted)...
VM isolationdata classificationshadow IThypervisor security - Question #637Research, Development and Collaboration
An electric car company hires an IT consulting company to improve the cybersecurity of us vehicles. Which of the following should achieve the BEST long-term result for the company?
secure SDLCautomotive securityembedded systemssecurity requirements - Question #638Technical Integration of Enterprise Security
An enterprise is configuring an SSL client-based VPN for certificate authentication. The trusted root certificate from the CA is imported into the firewall, and the VPN configurati...
SSL VPNcertificate authenticationcipher suitesPKI troubleshooting - Question #639Research, Development and Collaboration
A software development firm wants to validate the use of standard libraries as part of the software development process. Each developer performs unit testing prior to committing ch...
static analysissecure SDLCcode repositoryDevSecOps - Question #640Enterprise Security Operations
A creative services firm has a limited security budget and staff. Due to its business model, the company sends and receives a high volume of files every day through the preferred m...
cloud sandboxmalware preventionfile transfer securitylimited budget controls - Question #641Enterprise Security Operations
During an audit, it was determined from a sample that four out of 20 former employees were still accessing their email accounts. An information security analyst is reviewing the ac...
access managementoffboarding processaudit validationidentity lifecycle - Question #642Risk Management
A healthcare company wants to increase the value of the data it collects on its patients by making the data available to third-party researchers for a fee. Which of the following B...
data anonymizationPII protectionhealthcare datadata sharing risk - Question #643Enterprise Security Architecture
The Chief Executive Officer )CEO) of a small company decides to use cloud computing to host critical corporate data for protection from natural disasters. The recommended solution...
public cloud adoptiondisaster recoverybusiness continuitycloud security - Question #644Research, Development and Collaboration
A development team releases updates to an application regularly. The application is compiled with several standard open-source security products that require a minimum version for...
open-source dependenciessoftware supply chainpatch managementthird-party libraries - Question #645Enterprise Security Operations
A penetration tester is given an assignment lo gain physical access to a secure facility with perimeter cameras. The secure facility does not accept visitors and entry is available...
physical penetration testingRFID cloningsocial engineeringphysical security bypass - Question #646Enterprise Security Operations
An attacker exploited an unpatched vulnerability in a web framework, and then used an application service account that had an insecure configuration to download a rootkit. The atta...
vulnerability managementservice account hardeningrootkitpatch management - Question #647Technical Integration of Enterprise Security
A video-game developer has received reports of players who are cheating. All game players each have five capabilities that are ranked on a scale of 1 to 10 points, with 10 total po...
TOC/TOUrace conditionapplication securitygame logic vulnerability - Question #648Risk Management
The Chief Executive Officer (CEO) of a fast-growing company no longer knows all the employees and is concerned about the company's intellectual property being stolen by an employee...
insider threatDLPIP protectionremote workforce - Question #649Enterprise Security Operations
Due to a recent breach, the Chief Executive Officer (CEO) has requested the following activities be conducted during incident response planning: - Involve business owners and stake...
incident response exercisestabletop exerciseIR planninglessons learned - Question #650Technical Integration of Enterprise Security
Several days after deploying an MDM for smartphone control, an organization began noticing anomalous behavior across the enterprise Security analysts observed the following: - Unau...
MDM securitySCEPPKI certificate issuancerooted device - Question #651Enterprise Security Operations
A security administrator is opening connectivity on a firewall between Organization A and Organization B Organization B just acquired Organization A. Which of the following risk mi...
network segmentationIPS/IDSmerger acquisition securitynetwork access control - Question #652Enterprise Security Architecture
An organization is facing budget constraints The Chief Technology Officer (CTO) wants to add a new marketing platform but the organization does not have the resources to obtain sep...
VM co-hostingdisparate security requirementsdata classificationvirtualization risk - Question #653Enterprise Security Architecture
A cloud architect needs to isolate the most sensitive portion of the network while maintaining hosting in a public cloud. Which of the following configurations can be employed to s...
hybrid cloudnetwork isolationpublic cloud architecturesensitive data hosting - Question #654Enterprise Security Architecture
A financial services company has proprietary trading algorithms, which were created and are maintained by a team of developers on their private source code repository. If the detai...
cloud tenancydata isolationproprietary data protectioncloud deployment models - Question #655Enterprise Security Operations
A security administrator is performing an audit of a local network used by company guests and executes a series of commands that generates the following output: Which of the follow...
ARP spoofingswitchport securitylayer 2 securitynetwork hardening - Question #656Technical Integration of Enterprise Security
An attacker wants to gain information about a company's database structure by probing the database listener. The attacker tries to manipulate the company's database to see if it ha...
database securityauthentication hardeningaccess controldatabase listener - Question #657Risk Management
An organization based in the United States is planning to expand its operations into the European market later in the year Legal counsel is exploring the additional requirements th...
GDPRdata privacyregulatory complianceinternational expansion - Question #658Enterprise Security Operations
A company is deploying a DIP solution and scanning workstations and network drives for documents that contain potential Pll and payment card data. The results of the first scan are...
DLPPIIdata classificationaccess control - Question #659Technical Integration of Enterprise Security
A security engineer wants to introduce key stretching techniques to the account database to make password guessing attacks more difficult. Which of the following should be consider...
key stretchingbcryptPBKDF2password hashing - Question #660Enterprise Security Operations
As part of an organization's ongoing vulnerability assessment program, the Chief Information Security Officer (CISO) wants to evaluate the organization's systems, personnel, and fa...
social engineeringphysical penetration testingtailgatingvishing - Question #661Enterprise Security Operations
A security engineer discovers a PC may have been breached and accessed by an outside agent. The engineer wants to find out how this breach occurred before remediating the damage. W...
digital forensicsincident responseevidence preservationforensic imaging - Question #662Enterprise Security Architecture
A hospital is using a functional magnetic resonance imaging (fMRI) scanner, which is controlled legacy desktop connected to the network. The manufacturer of the fMRI will not suppo...
legacy systemsnetwork segmentationmedical devicesOT security - Question #663Risk Management
A Chief Information Security Officer (CISO) has created a survey that will be distributed to managers of mission-critical functions across the organization. The survey requires the...
business impact analysisrecovery time objectiverecovery point objectivebusiness continuity - Question #664Enterprise Security Operations
Following a recent security incident on a web server the security analyst takes HTTP traffic captures for further investigation. The analyst suspects certain jpg files have importa...
network forensicstraffic analysissteganographypacket capture