CAS-003 Exam Questions
947 real CAS-003 exam questions with expert-verified answers and explanations. Page 14 of 19.
- Question #665Risk Management
A company has completed the implementation of technical and management controls as required by its adopted security, ponies and standards. The implementation took two years and con...
residual riskrisk acceptancerisk treatmentsecurity controls - Question #666Risk Management
An e-commerce company that provides payment gateways is concerned about the growing expense and time associated with PCI audits of its payment gateways and external audits by custo...
PCI-DSSaudit scope reductioncompliance attestationISO certification - Question #667Enterprise Security Operations
An employee decides to log into an authorized system. The system does not prompt the employee for authentication prior to granting access to the console, and it cannot authenticate...
Smurf attackauthentication bypassDDoS amplificationnetwork attacks - Question #668Enterprise Security Operations
An engineer wants to assess the OS security configurations on a company's servers. The engineer has downloaded some files to orchestrate configuration checks. When the engineer ope...
SCAPconfiguration compliancesecurity baselinesvulnerability assessment - Question #669Technical Integration of Enterprise Security
A company is implementing a new secure identity application, given the following requirements - The cryptographic secrets used in the application must never be exposed to users or...
mobile securityNFCbiometricsbadge reader integration - Question #670Technical Integration of Enterprise Security
A small firm's newly created website has several design flaws. The developer created the website to be fully compatible with ActiveX scripts in order to use various digital certifi...
mobile codeActiveXJava appletsbrowser sandboxing - Question #671Enterprise Security Architecture
An organization is integrating an ICS and wants to ensure the system is cyber resilient. Unfortunately, many of the specialized components are legacy systems that cannot be patched...
ICS securitylegacy systemscyber resilienceOT vulnerability management - Question #672Technical Integration of Enterprise Security
A company wants to implement a cloud-based security solution that will sinkhole malicious DNS requests. The security administrator has implemented technical controls to direct DNS...
DNS sinkholingpolicy routingDNS securityendpoint DNS enforcement - Question #673Technical Integration of Enterprise Security
The Chief Information Security Officer (CISO) of an organization is concerned with the transmission of cleartext authentication information across the enterprise. A security assess...
LDAPScleartext authenticationHTTPS enforcementdirectory services - Question #675Risk Management
Which of the following risks does expanding business into a foreign country carry?
data sovereigntyinternational expansionregulatory compliancegeopolitical risk - Question #676Risk Management
A large, multinational company currently has two separate databases. One is used for ERP while the second is used for CRM To consolidate services and infrastructure, it is proposed...
regulatory compliancedatabase consolidationERP/CRM integrationdata governance - Question #677Technical Integration of Enterprise Security
A company uses AD and RADIUS to authenticate VPN and WiFi connections. The Chief Information Security Officer (CISO) initiates a project to extend a third-party MFA solution to VPN...
RADIUSNAS-Port-TypeAAA configurationMFA integration - Question #678Enterprise Security Architecture
A PaaS provider deployed a new product using a DevOps methodology. Because DevOps is used to support both development and production assets inherent separation of duties is limited...
DevOps securityseparation of dutiescompensating controlsPaaS compliance - Question #679Enterprise Security Architecture
A red team is able to connect a laptop with penetration testing tools directly into an open network port. The team then is able to take advantage of a vulnerability on the domain c...
802.1Xnetwork access controlcertificate-based authenticationprivilege escalation - Question #680Enterprise Security Operations
Confidential information related to ApplicationA. Application B and Project X appears to have been leaked to a competitor. After consulting with the legal team, the IR team is advi...
legal holdevidence preservationincident responsedata breach - Question #681Enterprise Security Architecture
A secure facility has a server room that currently is controlled by a simple lock and key. and several administrators have copies of the key. To maintain regulatory compliance, a s...
biometric authenticationphysical access controlfalse acceptance rateMFA - Question #682Technical Integration of Enterprise Security
A security engineer is helping the web developers assess a new corporate web application The application will be Internet facing so the engineer makes the following recommendation:...
cookie securitySecure flagSameSite attributeweb application security - Question #683Enterprise Security Operations
A company is the victim of a phishing and spear-phishing campaign. Users are Clicking on website links that look like common bank sites and entering their credentials accidentally....
phishing defensespam filteringcontent filteringlayered security - Question #684Risk Management
A company is purchasing an application that will be used to manage all IT assets as well as provide an incident and problem management solution for IT activity. The company narrows...
risk appetiterisk avoidancerisk treatmentrisk acceptance - Question #685Enterprise Security Operations
An internal penetration tester finds a legacy application that takes measurement input made in a text box and outputs a specific string of text related to industry requirements. Th...
fuzzingblack box testinglegacy applicationspenetration testing - Question #686Enterprise Security Operations
A security analyst is reviewing weekly email reports and finds an average of 1.000 emails received daily from the internal security alert email address. Which of the following shou...
alert fatiguesecurity monitoringSIEM tuningseparation of duties - Question #687Technical Integration of Enterprise Security
An engineer needs to provide access to company resources for several offshore contractors. The contractors require: - Access to a number of applications, including internal website...
VDIVPNremote accesssecure offshore access - Question #688Research, Development and Collaboration
An application development company implements object reuse to reduce life-cycle costs for the company and its clients. Despite the overall cost savings, which of the following BEST...
object reusehomogeneous vulnerabilitiesSDLC securitysoftware supply chain - Question #689Enterprise Security Architecture
A company recently experienced a period of rapid growth, and it now needs to move to a more scalable cloud-based solution. Historically, salespeople have maintained separate system...
data separationcloud migrationnetwork segmentationmulti-tenancy - Question #690Enterprise Security Architecture
A company is in the process of re-architecting its sensitive system infrastructure to take advantage of on-demand computing through a public cloud provider. The system to be migrat...
hybrid cloud architecturedirect connectlatency and integritycloud migration - Question #691Enterprise Security Operations
An enterprise solution requires a central monitoring platform to address the growing networks of various departments and agencies that connect to the network. The current vendor pr...
SIEM scalabilityenterprise monitoringheterogeneous devicesnetwork monitoring - Question #692Enterprise Security Operations
The SOC has noticed an unusual volume of traffic coming from an open WiFi guest network that appears correlated with a broader network slowdown. The network team is unavailable to...
DNS tunnelingguest network securitytraffic analysisnetwork anomaly detection - Question #693Enterprise Security Operations
Following the merger of two large companies the newly combined security team is overwhelmed by the volume of logs flowing from the IT systems. The company's data retention schedule...
SIEMlog managementdata retentionsecurity operations - Question #694Risk Management
As part of a systems modernization program, the use of a weak encryption algorithm is identified m a wet se-vices API. The client using the API is unable to upgrade the system on i...
risk treatmentcompensating controlsACLweak encryption - Question #695Technical Integration of Enterprise Security
A new employee is plugged into the network on a BYOD machine but cannot access the network. Which of the following must be configured so the employee can connect to the network?
BYODVPNnetwork access controlport security - Question #696Technical Integration of Enterprise Security
A company has deployed MFA Some employees, however, report they ate not gelling a notification on their mobile device. Other employees report they downloaded a common authenticates...
MFApush notificationsauthenticator appsOpenID Connect - Question #697Enterprise Security Architecture
A company wants to secure a newly developed application that is used to access sensitive information and data from corporate resources. The application was developed by a third- pa...
mobile securitycertificate pinningdata interceptionVPN - Question #698Enterprise Security Operations
A security engineer is looking at a DNS server following a known incident. The engineer sees the following command as the most recent entry in the server's shell history: id ^f=iev...
digital forensicsdisk cloningdd commandincident analysis - Question #699Enterprise Security Operations
The security configuration management policy states that all patches must undergo testing procedures before being moved into production. The sec... analyst notices a single web app...
patch managementconfiguration managementanomaly detectionincident response - Question #703Enterprise Security Architecture
A security analyst has received the following requirements for the implementation of enterprise credential management software. - The software must have traceability back to an ind...
credential managementPAMencryption at restprivileged access - Question #704Risk Management
To meet a SLA, which of the following documents should be drafted, defining the company's internal interdependent unit responsibilities and delivery timelines.
OLASLAservice agreementsinternal interdependencies - Question #705Research, Development and Collaboration
The security administrator of a small firm wants to stay current on the latest security vulnerabilities and attack vectors being used by crime syndicates and nation-states. The inf...
threat intelligencethreat data feedsvulnerability researchCTI - Question #706Risk Management
An organization is moving internal core data-processing functions related to customer data to a global public cloud provider that uses aggregated services from other partner organi...
cloud migrationdata sovereigntydata privacy regulationsthird-party risk - Question #707Enterprise Security Architecture
A global company has decided to implement a cross-platform baseline of security settings for all company laptops. A security engineer is planning and executing the project. Which o...
security baselineMDMGPOendpoint hardening - Question #708Enterprise Security Operations
A security administrator is investigating an incident involving suspicious word processing documents on an employee's computer, which was found powered off in the employee's office...
digital forensicsfile carvingunallocated disk spaceforensic tools - Question #709Enterprise Security Operations
The email administrator must reduce the number of phishing emails by utilizing more appropriate security controls. The following configurations already are in place - Keyword Mocki...
anti-phishingemail securityBayesian filteringemail gateway - Question #710Technical Integration of Enterprise Security
Within the past six months, a company has experienced a series of attacks directed at various collaboration tools. Additionally, sensitive information was compromised during a rece...
collaboration securityinstant messagingVoIPdigital signatures - Question #711Research, Development and Collaboration
A government entity is developing requirements for an RFP to acquire a biometric authentication system. When developing these requirements, which of the following considerations is...
biometric authenticationSRTMrequirements validationregulatory compliance - Question #712Enterprise Security Architecture
A SaaS provider decides to offer data storage as a service. For simplicity, the company wants to make the service available over industry standard APIs, routable over the public In...
SaaS securityAPI securityMFAdata protection - Question #713Enterprise Security Architecture
A security administrator wants to stand up a NIPS that is multilayered and can incorporate many security technologies into a single platform. The product should have diverse capabi...
UTMNIPSunified threat managementnetwork security platform - Question #714Risk Management
The Chief Financial Officer (CFO) of an organization wants the IT department to add the CFO's account to the domain administrator group. The IT department thinks this is nsky and w...
separation of dutiesleast privilegedomain administratoraccess control - Question #715Enterprise Security Architecture
A company is trying to resolve the following issues related to its web servers and Internet presence: - The company's security rating declined on multiple occasions when it failed...
TLS certificate managementreverse proxyIPv6 addressingWAF deployment - Question #716Enterprise Security Architecture
A manufacturing company employs SCADA systems to drive assembly lines across geographically dispersed sites. Therefore, the company must use the Internet to transport control messa...
SCADA securityICS/OT isolationsite-to-site VPNpatch management - Question #717Risk Management
The results of an external penetration test for a software development company show a small number of applications account for the largest number of findings. While analyzing the c...
WAFnetwork segmentationcompliance riskACL - Question #718Risk Management
The Chief Information Security Officer (CISO) is preparing a requirements matrix scorecard for a new security tool the company plans to purchase. Feedback from which of the followi...
vendor selectionRFPprocurementsecurity requirements