CAS-003 Exam Questions
947 real CAS-003 exam questions with expert-verified answers and explanations. Page 16 of 19.
- Question #775Enterprise Security Operations
A penetration tester is on an active engagement and has access to a remote system. The penetration tester wants to bypass the DLP, which is blocking emails that are encrypted or co...
steganographyDLP bypassdata exfiltrationpenetration testing - Question #776Risk Management
An organization that develops military technology is considering expansion into a foreign country. The organization's owners want to understand the risks associated with such an ex...
tabletop assessmentrisk assessmentinternational expansionthreat analysis - Question #777Technical Integration of Enterprise Security
A company that uses AD is migrating services from LDAP to secure LDAP. During the pilot phase, services are not connecting properly to secure LDAP. Block is an except of output fro...
secure LDAPPKI certificatesport configurationdirectory services - Question #778Enterprise Security Operations
A threat analyst notices the following URL while going through the HTTP logs. Which of the following attack types is the threat analyst seeing?
XSScross-site scriptingHTTP log analysisweb attack identification - Question #779Risk Management
The Chief information Officer (CIO) of a large bank, which uses multiple third-party organizations to deliver a service, is concerned about the handling and security of customer da...
vendor risk managementthird-party riskdata governancesupplier assessment - Question #780Enterprise Security Operations
A human resources employee receives a call from an individual who is representing a background verification firm that is conducting a background check on a prospective candidate. T...
pretextingsocial engineeringransomware deliveryhuman factors - Question #781Risk Management
A company requires a task to be carried by more than one person concurrently. This is an example of:
separation of dutiesdual controlaccess controlleast privilege - Question #782Enterprise Security Architecture
A health company has reached the physical and computing capabilities in its datacenter, but the computing demand continues to increase. The infrastructure is fully virtualized and...
cloud computinghealthcare compliancesingle-tenancyvirtualization - Question #783Enterprise Security Architecture
A company has decided to move an ERP application to a public cloud vendor. The company wants to replicate some of its global policies from on premises to cloud. The policies includ...
CASBcloud access security brokerprivileged access managementERP security - Question #784Enterprise Security Operations
A security analyst is investigating a series of suspicious emails by employees to the security team. The email appear to come from a current business partner and do not contain ima...
email securityincident responsethreat investigationbusiness partner communication - Question #785Technical Integration of Enterprise Security
A financial services company wants to migrate its email services from on-premises servers to a cloud-based email solution. The Chief information Security Officer (CISO) must brief...
DLPcloud email securitydata exfiltration preventionanti-malware - Question #786Risk Management
Which of the following BEST sets expectation between the security team and business units within an organization?
business impact analysissecurity governanceSLAstakeholder communication - Question #787Enterprise Security Architecture
A small company needs to reduce its operating costs. vendors have proposed solutions, which all focus on management of the company's website and services. The Chief information Sec...
community cloudcloud service modelscost reductionmulti-tenancy - Question #788Enterprise Security Operations
A security is assisting the marketing department with ensuring the security of the organization's social media platforms. The two main concerns are: The Chief marketing officer (CM...
MFAshared credentialssocial media securityauthentication controls - Question #789Enterprise Security Architecture
A security engineer at a company is designing a system to mitigate recent setbacks caused competitors that are beating the company to market with the new products. Several of the p...
DLPintellectual property protectioninsider threatcompetitive intelligence - Question #790Technical Integration of Enterprise Security
The Chief information Officer (CIO) asks the system administrator to improve email security at the company based on the following requirements: * Transaction being requested by una...
DLPcloud email securitysandboxingdata exfiltration prevention - Question #791Technical Integration of Enterprise Security
A company that all mobile devices be encrypted, commensurate with the full disk encryption scheme of assets, such as workstation, servers, and laptops. Which of the following will...
MDMmobile encryptionkey escrowfull disk encryption - Question #792Enterprise Security Operations
A company is outsourcing to an MSSP that performs managed detection and response services. The MSSP requires a server to be placed inside the network as a log aggregate and allows...
MSSPlog aggregationencryption in transitmulti-tenancy data remnants - Question #793Risk Management
A cybersecurity analyst created the following tables to help determine the maximum budget amount the business can justify spending on an improved email filtering system: Which of t...
cost-benefit analysisemail filteringALE calculationrisk quantification - Question #794Enterprise Security Operations
Ann, a CIRT member, is conducting incident response activities on a network that consists of several hundred virtual servers and thousands of endpoints and users. The network gener...
incident responselog reductionSIEMevidence collection - Question #795Technical Integration of Enterprise Security
A security engineer is troubleshooting an issue in which an employee is getting an IP address in the range on the wired network. The engineer plus another PC into the same port, an...
802.1xVLAN assignmentDHCPnetwork authentication - Question #796Enterprise Security Operations
Immediately following the report of a potential breach, a security engineer creates a forensic image of the server in question as part of the organization incident response procedu...
digital forensicsforensic imaginghash integritychain of custody - Question #797Enterprise Security Operations
A company in the financial sector receives a substantial number of customer transaction requests via email. While doing a root-cause analysis conceding a security breach, the CIRT...
SIEMhost-based firewallincident detectionlog management - Question #798Risk Management
A system administrator at a medical imaging company discovers protected health information (PHI) on a general-purpose file server. Which of the following steps should the administr...
PHIHIPAA compliancedata classificationregulatory response - Question #799Enterprise Security Operations
A security analyst is reading the results of a successful exploit that was recently conducted by third-party penetration testers. The testers reverse engineered a privileged execut...
TOC/TOUrace conditionprivilege escalationreverse engineering - Question #800Enterprise Security Operations
A financial institution has several that currently employ the following controls: * The severs follow a monthly patching cycle. * All changes must go through a change management pr...
change managementfile integrity monitoringunauthorized changesaudit logging - Question #802Enterprise Security Operations
An analyst execute a vulnerability scan against an internet-facing DNS server and receives the following report: - Vulnerabilities in Kernel-Mode Driver Could Allow Elevation of Pr...
vulnerability prioritizationDNS RCEexploitation frameworkinternet-facing server - Question #803Risk Management
The Chief information Officer (CIO) wants to establish a non-banding agreement with a third party that outlines the objectives of the mutual arrangement dealing with data transfers...
MOUthird-party agreementsdata transfervendor management - Question #804Enterprise Security Operations
A security analyst is trying to identify the source of a recent data loss incident. The analyst has reviewed all the for the time surrounding the identified all the assets on the n...
data loss investigationstatic code analysisapplication forensicsincident response - Question #805Risk Management
Which of the following controls primarily detects abuse of privilege but does not prevent it?
detective controlsprivilege abusejob rotationaccess control - Question #806Technical Integration of Enterprise Security
A company provides guest WiFi access to the internet and physically separates the guest network from the company's internal WIFI. Due to a recent incident in which an attacker gain...
WPA2 EnterpriseEAP-TLSPKI certificateswireless security - Question #807Risk Management
The goal of a Chief information Security Officer (CISO) providing up-to-date metrics to a bank's risk committee is to ensure:
security metricsrisk reportingcybersecurity governancerisk committee - Question #808Enterprise Security Operations
A cybersecurity engineer analyst a system for vulnerabilities. The tool created an OVAL. Results document as output. Which of the following would enable the engineer to interpret t...
OVALSCAPvulnerability scanningXML stylesheet - Question #809Risk Management
A Chief information Security Officer (CISO) is developing corrective-action plans based on the following from a vulnerability scan of internal hosts: Which of the following MOST ap...
vulnerability managementcorrective actionpatch dependenciesrisk remediation - Question #810Enterprise Security Operations
The Chief information Security Officer (CISO) of a small locate bank has a compliance requirement that a third-party penetration test of the core banking application must be conduc...
penetration testingcompliance requirementstesting methodologiesbanking security - Question #811Research, Development and Collaboration
An application developer is including third-party background security fixes in an application. The fixes seem to resolve a currently identified security issue. However, when the ap...
regression testingSDLC securityvulnerability recurrencesoftware testing - Question #812Technical Integration of Enterprise Security
A security analyst is validating the MAC policy on a set of Android devices. The policy was written to ensure non-critical applications are unable to access certain resources. When...
SELinuxMAC policyAndroid securityenforcing mode - Question #813Enterprise Security Operations
A cybersecurity analyst receives a ticket that indicates a potential incident is occurring. There has been a large in log files generated by a generated by a website containing a `...
log analysisincident triageweb trafficlog reduction - Question #814Enterprise Security Operations
The OS on several servers crashed around the same time for an unknown reason. The servers were restored to working condition, and all file integrity was verified. Which of the foll...
root cause analysisincident responsepost-incident reviewserver stability - Question #815Risk Management
A company is repeatedly being breached by hackers who valid credentials. The company's Chief information Security Officer (CISO) has installed multiple controls for authenticating...
identity proofingauthentication controlscredential theftmulti-factor authentication - Question #816Enterprise Security Operations
A security auditor needs to review the manner in which an entertainment device operates. The auditor is analyzing the output of a port scanning tool to determine the next steps in...
SCAP assessmentport scanningIoT securitysecurity review - Question #817Technical Integration of Enterprise Security
An engineering team is developing and deploying a fleet of mobile devices to be used for specialized inventory management purposes. These devices should: - Be based on open-source...
mobile device managementAndroid securityapplication wrappingMAC sepolicy - Question #818Enterprise Security Operations
A company's employees are not permitted to access company systems while traveling internationally. The company email system is configured to block logins based on geographic locati...
geolocation blockingVPN bypassmobile email securityGPS spoofing - Question #819Enterprise Security Architecture
A company's bandwidth has increased an average of 20% year over year, but the current firewall will not handle future bandwidth. At the current bandwidth of 1 Gbps, the firewall wi...
firewall capacity planningbandwidth forecastingnetwork securitycost optimization - Question #820Risk Management
A company donates many of its laptops to a non-profit organization after completing a refresh cycle. The help desk currently backs up the user data and deletes the users' profiles...
asset disposaldata sanitizationdrive wipingendpoint decommission - Question #821Research, Development and Collaboration
A major OS vendor implements an IDE-integrated tool that alerts developers on the use of insecure and deprecated С code functions. Using which of the following functions would yiel...
secure codingdeprecated C functionsbuffer overflowstatic analysis - Question #822Enterprise Security Architecture
A company is planning to undergo a P2V project to improve resource utilization, redundancy, and failover across its two datacenters. A consultant has provided a private cloud desig...
virtualization securityvTPMhypervisor integrityP2V migration - Question #823Enterprise Security Architecture
A company is deploying laptops to replace all current desktop endpoints. This increases the risk of data loss. Which of the following is the BEST solution to address this risk?
full disk encryptionendpoint securitydata loss preventionmobile endpoints - Question #824Enterprise Security Operations
An ICS security engineer is performing assessment at a bank in Chicago. The engineer reviews the following output: Which of the following tools is the engineer using to provide thi...
ShodanICS securityOSINTindustrial control systems - Question #825Technical Integration of Enterprise Security
A company recently developed a new mobile application that will be used to access a sensitive system. The application and the system have the following requirements: The applicatio...
mobile app deploymentUSB OTGOTA updatessideloading