CAS-003 Exam Questions
947 real CAS-003 exam questions with expert-verified answers and explanations. Page 18 of 19.
- Question #876Enterprise Security Architecture
To reduce costs, an organization, has decided it will no longer support corporate phones. All employees must use a BYOD device to access the company's collaboration services, which...
BYODMAMMFAmobile device management - Question #877Enterprise Security Operations
A security analyst is reviewing the following event: The packet appears to contain a malicious payload that is being delivered to the endpoint through the gateway firewall. Which o...
NIPSnetwork intrusion preventionmalwaregateway security - Question #878Risk Management
A Chief Information Security Officer (CISO) is developing corrective-action plans based on the following output from a vulnerability scan of internal hosts: Which of the following...
vulnerability scanningbusiness impact assessmentcorrective actionpatch management - Question #880Risk Management
Privacy standards generally prohibit the public disclosure of:
privacy standardsPIINDAdata disclosure - Question #881Enterprise Security Architecture
Two major aircraft manufacturers are in the process of merging their assets and forming a single enterprise network. One of the manufacturers maintains its ICS systems on the same...
ICS securityOT/IT convergencenetwork segmentationlegacy systems - Question #882Enterprise Security Operations
A group of security consultants is conducting an assessment of a customer's network across multiple physical locations. To save time, the customer has allowed the consultants to in...
penetration testingpivot pointsocial engineeringred team - Question #883Enterprise Security Operations
A large organization suffers a data breach after one staff member inadvertently shares a document on a corporate-approved, file-sharing, cloud-collaboration service. The security a...
CASBDLPcloud data loss preventionremote access - Question #884Risk Management
A Chief information Security Officer (CISO) has launched to create a rebuts BCP/DR plan for the entire company. As part of the initiative , the security team must gather data suppo...
BCPDRbusiness impact analysisrecovery planning - Question #885Enterprise Security Operations
A company protects privileged accounts by using hardware keys as a second factor. A security engineer receives an error while attempting to authenticate with a hardware key for the...
hardware tokensMFAauthenticationtoken registration - Question #886Technical Integration of Enterprise Security
The Chief Information Officer (CIO) asks the systems administrator to improve email security at the company based on the following requirements: 1. Do not use two-factor authentica...
S/MIMEemail securityTLSdigital signatures - Question #887Risk Management
A small company is implementing a new technology that promises greater performance but does not abide by accepted RFCs. Which of the following should the company do to ensure the r...
vendor risknon-standard protocolssystem security planrisk documentation - Question #888Risk Management
The president of an online retail company has decided the company needs to increase its market size by targeting more countries in order to increase sales. All customer data is cur...
data sovereigntyinternational compliancejurisdictionprivacy laws - Question #889Enterprise Security Operations
A company hosts a web-based application that is accessed by customers worldwide. A code review has discovered known vulnerabilities in the company's server application, which is ma...
dependency managementpatch managementPython librariesvulnerability remediation - Question #890Enterprise Security Operations
An organization recently experienced losses caused by users who installed applications from unauthorized sources on their smartphones. The organization wants to reduce the risk of...
MAMmobile device managementapplication whitelistingenterprise mobile security - Question #891Enterprise Security Architecture
An organization wishes to implement cloud computing, but it is not sure which service to choose. The organization wants to be able to share Tiles, collaborate, and use applications...
cloud service modelsSaaSIaaScloud deployment - Question #893Technical Integration of Enterprise Security
A system integrator wants to assess the security of the application binaries delivered by its subcontracted vendors. The vendors do not deliver source code as a part of their contr...
binary analysisreverse engineeringstatic analysiscode review without source - Question #894Enterprise Security Operations
A legacy SCADA system is m place in a manufacturing facility to ensure proper facility operations. Recent industry reports made available to the security team state similar legacy...
SCADA securityICS monitoringnetwork IDScontinuous monitoring - Question #895Enterprise Security Architecture
While standing a proof-of-concept solution with a vendor, the following direction was given of connections to the default environments. Which of the following is using used to secu...
environment separationVLAN segmentationDMZlogical access controls - Question #896Enterprise Security Architecture
Employees who travel internationally have been issued corporate mobile devices. When traveling through border security employees report border police officers have asked them to po...
mobile device securityfull-device encryptioninternational traveldata protection - Question #897Enterprise Security Operations
A security engineer is performing a routine audit of a company's decommissioned devices. The current process involves a third-party firm removing the hard drive from a company devi...
data sanitizationhard drive disposalcluster tipssecure decommissioning - Question #898Enterprise Security Architecture
An organization recently suffered a high-impact loss due to a zero-day vulnerability exploited in a concentrator enabling iPSec VPN access for users. The attack included a pivot in...
VPN securityzero-day mitigationnetwork segmentationIPS/IDS - Question #899Enterprise Security Operations
A security analyst is reviewing the security of a company's public-facing servers. After some research the analyst discovers the following on a public pastebin website. Which of th...
credential exposurepastebinincident responsedatabase security - Question #900Enterprise Security Architecture
A cloud architect is moving a distributed system to an external cloud environment. The company must be able to: - Administer the server software at OS and application levels - Show...
cloud service modelsIaaSsingle-tenancyMSSP - Question #901Enterprise Security Operations
Following a major security modem that resulted in a significant loss of revenue and extended loss of server availability, a new Chief Information Security Officer (CISO) conducts a...
incident responselessons learnedroot cause analysisCISO - Question #902Technical Integration of Enterprise Security
A security analyst is examining threats with the following code function: Which of the following threats should the security analyst report1?
third-party JavaScriptweb application securityXSScode analysis - Question #903Risk Management
The Chief Information Security Officer (CISO) developed a robust plan to address both internal and external vulnerabilities due to an increase in ransomware attacks on the networks...
threat modelingransomwaresecurity control failurerisk assessment - Question #904Enterprise Security Architecture
A corporation with a BYOO policy is very concerned about issues that may arise from data ownership. The corporation is investigating a new MOM solution and has gathered the followi...
MDMBYODgeofencingmobile device management - Question #905Technical Integration of Enterprise Security
The HVAC and fire suppression systems that were recently deployed at multiple locations are susceptible to a new vulnerability. A security engineer needs to ensure the vulnerabilit...
ICS/SCADAOT securityIPS signaturesnetwork segmentation - Question #906Technical Integration of Enterprise Security
The Chief Information Security Officer (CISO) of a power generation facility s concerned about being able to detect missing security updates on the critical infrastructure in use a...
SCADApassive vulnerability scanningdata diodecritical infrastructure - Question #907Risk Management
Which of the following is the primary cybersecurity-related difference between the goals of a risk assessment and a business impact analysts?
risk assessmentBIAALESLE - Question #908Enterprise Security Operations
An organization's email filler is an ineffective control and as a result employees have been constantly receiving phishing emails. As part of a security incident investigation a se...
EDRDLPphishing investigationincident response - Question #909Enterprise Security Operations
After multiple availability issues a systems administrator is reviewing the following metrics from the web server farm, which is configured to serve the company's e-commerce site:...
load balancinghigh availabilityweb server performancee-commerce - Question #910Technical Integration of Enterprise Security
A company recently developed a new mobile application that will be used to access a sensitive system. The application and the system have the following requirements: - The applicat...
mobile application deploymentinternal app storesideloadingmTLS - Question #911Risk Management
Following a recent disaster a business activates its DRP. The business is operational again within 60 minutes. The business has multiple geographically dispersed locations that hav...
disaster recoveryDRPrecovery objectivesbusiness continuity - Question #913Technical Integration of Enterprise Security
A network engineer recently configured a new wireless network that has issues with security stability and performance. After auditing the configurations the engineer discovers some...
wireless securitychannel configurationRF interferenceWPA2 - Question #914Technical Integration of Enterprise Security
A developer is writing a new mobile application that employees will use to connect to an Internet- facing sensitive system. The security team is concerned with MITM attacks against...
certificate pinningMITM protectionmobile securityTLS - Question #915Enterprise Security Operations
An analyst is testing the security of a server and attempting to infiltrate the network. The analyst is able to obtain the following output after running some tools on the server....
penetration testingpassword auditingblank passwordsprivilege escalation - Question #916Enterprise Security Architecture
A network engineer is concerned about hosting web SFTP. and email services m a single DMZ that is hosted in the same security zone. This could potentially allow lateral movement wi...
DMZ segmentationsecurity zonesACLslateral movement - Question #917Enterprise Security Operations
A company has a DLP system with the following capabilities: - Text examination - Optical character recognition - File type validation - Multilingual translation of key words and ph...
DLP evasionsteganographydata exfiltrationinsider threat - Question #918Risk Management
A company's potential new vendors are asking for detailed network and traffic information so they can properly size a firewall. Which of the following would work BEST to protect th...
NDAvendor managementprocurement securitythird-party risk - Question #919Enterprise Security Architecture
A company s design team is increasingly concerned about intellectual property theft Members of the team often travel to suppliers' offices where they collaborate and share access t...
MDMfull disk encryptionintellectual propertymobile security - Question #920Technical Integration of Enterprise Security
A company deploys a system to use device and user certificates for network authentication. Previously, the company only used separate certificates to send receive encrypted email....
PKIS/MIMEcertificate managementemail encryption - Question #921Research, Development and Collaboration
A developer implements the following code snippet: Which of the following vulnerabilities does this code snippet resolve?
buffer overflowsecure codinginput validationvulnerability remediation - Question #922Risk Management
A security program was allocated S2 million in funding far tie year. The cybersecurity team identified the following potential projects to deliver: Which of the following solutions...
security budgetrisk prioritizationUEBASOC investment - Question #923Risk Management
A line-of-business manager has deeded in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of act...
third-party riskrisk assessmentvendor due diligencesupply chain - Question #924Technical Integration of Enterprise Security
A security analyst discovered the following request to a public-facing web server in a log: The security analyst recommended an extra protection, so the web application can resist...
cookie securityHttpOnly flagSecure flagsession hijacking - Question #925Enterprise Security Architecture
A security officer is reviewing the following evidence associated with a recent penetration test: The lest results show this host is vulnerable. The security officer investigates f...
NAC802.1Xrogue device detectionnetwork access control - Question #926Technical Integration of Enterprise Security
A company needs to deploy a home assistant that has the following requirement: 1. Revalidate identity when sensitive personal information is accessed and when there is a change m d...
OAuthtoken managementadaptive authenticationdevice flow - Question #927Enterprise Security Operations
A Chief Information Security Officer (CISO) wants to set up a SOC to respond to security threats and events more quickly. The SOC must have the following capacities: - Real-time re...
SIEMSOC capabilitiesthreat intelligencesecurity analytics - Question #928Enterprise Security Operations
A recent incident revealed a log entry was modified alter its original creation. Which of the following technologies would BEST ensure end user systems are able to defend against f...
log integritylog tamperingaudit trailblockchain