CAS-003 Exam Questions
947 real CAS-003 exam questions with expert-verified answers and explanations. Page 17 of 19.
- Question #826Enterprise Security Operations
Following a major security incident that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conduct...
incident responselessons learnedroot cause analysispost-incident review - Question #827Risk Management
A security program was allocated $2 million in funding for the year. The cybersecurity team identified the following potential projects to deliver: Which of the following solutions...
security budgetrisk reduction prioritizationUEBASOC - Question #828Research, Development and Collaboration
A software company tripled its workforce by hiring numerous early career developers out of college. The senior development team has a long-running history of secure coding, mostly...
secure coding trainingSDLCautomated testingdeveloper education - Question #829Technical Integration of Enterprise Security
A security engineer has just been embedded in an agile development team to ensure security practices are maintained during frequent release cycles. A new web application includes a...
fuzzinginput validation testingweb application securityerror handling - Question #830Enterprise Security Architecture
The HVAC and fire suppression systems that were recently deployed at multiple locations are susceptible to a new vulnerability. A security engineer needs to ensure the vulnerabilit...
network segmentationOT securityICS vulnerabilityIPS signatures - Question #831Research, Development and Collaboration
An aircraft manufacturer is developing software that will perform automatic flight control (auto- pilot). Given the high safety criticality of the software, the developer can BEST...
safety-critical softwareformal methodssoftware correctnessavionics security - Question #832Research, Development and Collaboration
An application developer is including third-party backported security fixes in an application. The fixes seem to resolve a currently identified security issue. However, when the ap...
regression testingbackported patchesSDLCvulnerability recurrence - Question #833Enterprise Security Operations
A forensic analyst must image the hard drive of a computer and store the image on a remote server. The analyst boots the computer with a live Linux distribution. Which of the follo...
digital forensicsdisk imagingSSH secure transferforensic acquisition - Question #834Enterprise Security Operations
A security engineer at a company is designing a system to mitigate recent setbacks caused by competitors that are beating the company to market with new products. Several of the pr...
data loss preventionintellectual property protectioninsider threatDLP - Question #835Risk Management
Which of the following risks does expanding business into a foreign country carry?
data sovereigntyinternational complianceregulatory riskcross-border data - Question #836Enterprise Security Operations
An analyst is testing the security of a server and attempting to infiltrate the network. The analyst is able to obtain the following output after running some tools on the server:...
penetration testingpassword crackingonline attacksattack tools - Question #837Risk Management
Following a recent disaster, a business activates its DRP. The business is operational again within 60 minutes. The business has multiple geographically dispersed locations that ha...
disaster recoveryDRPrecovery objectivesbusiness continuity - Question #838Technical Integration of Enterprise Security
A corporation with a BYOD policy is very concerned about issues that may arise from data ownership. The corporation is investigating a new MDM solution and has gathered the followi...
BYODMDMgeofencingcontainerization - Question #839Enterprise Security Operations
A security engineer needs to implement controls that will prevent the theft of data by insiders who have valid credentials. Recent incidents were carried out with mobile and wearab...
DLPinsider threatBluetoothdata exfiltration - Question #840Risk Management
During an audit, an information security analyst discovers accounts that are still assigned to employees who no longer work for the company and new accounts that need to be verifie...
identity lifecycleaccess reviewaccount managementaudit - Question #841Risk Management
A Chief Information Security Officer (CISO) wants to obtain data from other organizations in the same industry related to recent attacks against industry targets. A partner firm in...
threat intelligencerisk analysisinformation sharingCERT - Question #842Risk Management
An organization has been the target of four phishing attacks in the last year. Each incident has cost the organization an average of $2,000. A security director researches addition...
phishingROI calculationsecurity investmentanti-phishing - Question #843Enterprise Security Operations
Several corporate users returned from an international trip with compromised operating systems on their cellular devices. Additionally, intelligence reports confirm some internatio...
mobile securityFOTAfirmware compromiseinternational travel - Question #844Technical Integration of Enterprise Security
A developer implements the following code snippet: Which of the following vulnerabilities does this code snippet resolve?
secure codinginformation disclosureapplication securityerror handling - Question #845Enterprise Security Architecture
The Chief Information Security Officer (CISO) of a power generation facility is concerned about being able to detect missing security updates on the critical infrastructure in use...
ICS/SCADAvulnerability scanningOT securitypassive monitoring - Question #846Enterprise Security Operations
Which of the following controls primarily detects abuse of privilege but does not prevent it?
access controlprivilege managementdetective controlsuser offboarding - Question #847Enterprise Security Operations
A company has a DLP system with the following capabilities: Text examination Optical character recognition File type validation Multilingual translation of key words and phrases Bl...
DLP evasionsteganographydata exfiltrationinsider threat - Question #848Enterprise Security Operations
A security analyst is responsible for the completion of a vulnerability assessment at a regional healthcare facility. The analyst reviews the following Nmap output: Which of the fo...
Nmapvulnerability scanningSMBnetwork reconnaissance - Question #849Technical Integration of Enterprise Security
A developer is concerned about input validation for a newly created shopping-cart application, which will be released soon on a popular website. Customers were previously able to m...
dynamic analysisinput validationapplication testingDAST - Question #850Enterprise Security Architecture
A factory-floor system uses critical, legacy, and unsupported application software to enable factory operations. A latent vulnerability was recently exposed, which permitted attack...
legacy systemscompensating controlsinput sanitizationunpatched vulnerabilities - Question #851Enterprise Security Architecture
While standing up a proof-of-concept solution with a vendor, the following direction was given for connections to the different environments: Which of the following is being used t...
VLAN segmentationDMZnetwork isolationenvironment separation - Question #852Technical Integration of Enterprise Security
A developer is writing a new mobile application that employees will use to connect to an Internet- facing sensitive system. The security team is concerned with MITM attacks against...
TLScertificate pinningMITM preventionmobile app security - Question #853Technical Integration of Enterprise Security
A company deploys a system to use device and user certificates for network authentication. Previously, the company only used separate certificates to send/receive encrypted email....
PKIS/MIMEcertificate managementencrypted email - Question #854Technical Integration of Enterprise Security
A security analyst is examining threats with the following code function: Which of the following threats should the security analyst report?
JavaScript securitythird-party codeclient-side attackscode analysis - Question #855Enterprise Security Operations
A security team wants to keep up with emerging threats more efficiently by automating NIDS signature development and deployment. Which of the following approaches would BEST suppor...
NIDS signaturesthreat intelligenceIOC feedsautomation - Question #856Technical Integration of Enterprise Security
A newly hired employee is trying to complete online training. When the employee logs on to the third-party service for training using known-good credentials through a SAML-based me...
SAMLidentity federationSSOIdP troubleshooting - Question #857Enterprise Security Architecture
A product owner is working with a security engineer to improve the security surrounding certificate revocation, which is important for the clients using a web application. The orga...
PKIcertificate revocationOCSP staplingCRL - Question #858Enterprise Security Operations
A security analyst is investigating an alert arising from an impossible travel pattern. Within the span of 30 minutes, the email system saw successful authentication from two IP ad...
anomaly detectionimpossible travelthreat investigationNTP synchronization - Question #859Risk Management
Company A is establishing a contractual relationship with Company B. The terms of the agreement are formalized in a document covering the payment terms, limitation of liability, an...
SLAMSAthird-party agreementslegal contracts - Question #860Enterprise Security Architecture
A cloud architect is moving a distributed system to an external cloud environment. The company must be able to: Administer the server software at OS and application levels. Show th...
cloud service modelsIaaSmulti-tenancycloud architecture - Question #861Enterprise Security Architecture
After multiple availability issues, a systems administrator is reviewing the following metrics from the web server farm, which is configured to serve the company's e-commerce site:...
load balancinghigh availabilityweb server farmavailability - Question #862Enterprise Security Architecture
A company's human resources department recently had its own shadow IT department spin up multiple VM guests on one host, each hosting a mixture of differently labeled data types (c...
virtualization securitydata classificationVM isolationshadow IT - Question #863Enterprise Security Operations
A legacy SCADA system is in place in a manufacturing facility to ensure proper facility operations. Recent industry reports made available to the security team state similar legacy...
ICS/SCADAOT securityNIDScontinuous monitoring - Question #864Risk Management
A line-of-business manager has decided, in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of a...
third-party riskvendor managementrisk assessmentsupply chain - Question #865Technical Integration of Enterprise Security
An organization uses an internal, web-based chat service that is served by an Apache HTTP daemon. A vulnerability scanner has identified this service is susceptible to a POODLE att...
SSL/TLSPOODLE attackApache configurationprotocol vulnerability - Question #866Technical Integration of Enterprise Security
The latest security scan of a web application reported multiple high vulnerabilities in session management. Which of the following is the BEST way to mitigate the issue?
session managementcookie securityHttpOnlyweb application security - Question #867Risk Management
Which of the following is the primary cybersecurity-related difference between the goals of a risk assessment and a business impact analysis?
risk assessmentBIAthreat analysisrisk methodology - Question #868Enterprise Security Operations
A security manager is creating an incident response plan for an organization. Executive management wants to designate a specific group of personnel to respond to incidents and an a...
incident responseCIRTthreat huntingsecurity teams - Question #869Enterprise Security Operations
A security analyst is testing a server and finds the following in the output of a vulnerability scan: Which of the following will the security analyst most likely use NEXT to explo...
vulnerability scanningpenetration testingexploitation frameworksecurity assessment - Question #870Enterprise Security Architecture
A company's design team is increasingly concerned about intellectual property theft. Members of the team often travel to suppliers' offices where they collaborate and share access...
data protectionIP theftVDIremote access security - Question #871Risk Management
The Chief Information Security Officer (CISO) developed a robust plan to address both internal and external vulnerabilities due to an increase in ransomware attacks on the network....
threat modelingransomwaresecurity program failureroot cause analysis - Question #872Risk Management
While reviewing wire transfer procedures, the Chief Information Security Officer (CISO) of a bank discovers a flaw in the policy that can potentially allow for some wire transfers...
residual riskcompensating controlsrisk terminologyrisk treatment - Question #873Enterprise Security Operations
A security analyst is reviewing the security of a company's public-facing servers. After some research, the analyst discovers the following on a public pastebin website. Which of t...
OSINTattack surfacevulnerability assessmentpastebin reconnaissance - Question #874Enterprise Security Operations
A recent incident revealed a log entry was modified after its original creation. Which of the following technologies would BEST ensure end user systems are able to defend against f...
log integrityaudit traillog tamperingdata archival - Question #875Enterprise Security Operations
An organization's email filter is an ineffective control, and as a result, employees have been constantly receiving phishing emails. As part of a security incident investigation, a...
EDRDLPphishing investigationendpoint security