CAS-003 Exam Questions
947 real CAS-003 exam questions with expert-verified answers and explanations. Page 19 of 19.
- Question #929Research, Development and Collaboration
A security engineer has just been embedded in an agile development team to ensure security practices are maintained during frequent release cycles. A new web application includes a...
fuzzingdynamic analysisweb application testingsecure SDLC - Question #930Enterprise Security Operations
A security analyst must carry out the incident response plan for a specific targeted attack that was detected by the security operations center. The director of network security wa...
incident responseroot cause analysisthreat recurrenceafter-action review - Question #931Risk Management
A company decides to procure only laptops that use permanent, solid-stale storage. Which of the following risk mitigation strategies BEST meets the company's requirement to ensure...
data destructionSSD secure erasedata sanitizationend-of-life - Question #932Risk Management
An organization is a subsidiary of a larger firm that provides managed IT and human resources controls to the subsidiary. The subsidiary determines the contract in place between th...
interoperability agreementISAthird-party contractsmanaged services - Question #933Enterprise Security Operations
An ICS security engineer is performing a security assessment at a bank in Chicago. The engineer reviews the following output: Which of the following tools is the engineer using the...
SCAPICS securitysecurity assessment toolsvulnerability scanning - Question #934Enterprise Security Operations
An attacker has discovered an organization's web server is vulnerability to Shellshock. The attack runs the following command on a Linux box against the server: Which of the follow...
Shellshockprivilege reductionweb server hardeningbash vulnerability - Question #935Risk Management
Historical information shows that a small aerospace R&D company has a lack of user security awareness and is susceptible to nation-state social-engineering attacks and zero-day exp...
threat modelingsecurity strategyCISO decision makingrisk prioritization - Question #936Research, Development and Collaboration
A security technician wants to learn about the latest zero-day threats and newly discovered vulnerabilities but does not have the budget to purchase a commercial threat intelligenc...
threat intelligenceCERTopen-source intelligencefree security resources - Question #937Enterprise Security Architecture
A company is implementing a new MFA initiative. The requirements for the second factor are as following: - It cannot be phished - It must work as a second factor for laptop logins...
multi-factor authenticationphishing-resistant MFAauthentication factorshardware security keys - Question #938Enterprise Security Operations
A security needs to deploy a file named boardconfig.mk to some company devices. the file contains the following information: Much of the following represents the goal of this file?
mobile securitydevice configurationplatform hardeningSymbian - Question #939Enterprise Security Operations
An incident response analyst is investigating a compromise on a application server within an organization. The analyst identifies an anomalous process that is executing and maintai...
incident responsememory forensicslive forensicsmalware analysis - Question #940Enterprise Security Operations
A company is concerned about insider threats and wants to perform a security assessment. The lead security engineer has identified business-critical applications about half of whic...
penetration testinginsider threatsecurity assessmentapplication security - Question #941Risk Management
A company has experienced negative publicity associated with users giving out their credentials accidentally or sharing intellectual secrets that were not property defined. The com...
social media policydata loss preventionsecurity awarenessinformation disclosure - Question #942Enterprise Security Operations
An analyst needs to obtain information about an organization as part of the initial phase of a black-box penetration test. Which of the following can the analyst use to gain intell...
passive reconnaissanceOSINTemail harvestingwhois - Question #943Research, Development and Collaboration
A consulting firm is performing RD on a machine teaming system to characterize a network environment for new clients rapidly. The goal is to be able to label service/consumer behav...
machine learninganomaly detectionnetwork baselinetraining data - Question #944Risk Management
An administrative control that is put in place to ensure one person cannot carry out a critical task independently is:
separation of dutiesadministrative controlsaccess controlleast privilege - Question #945Enterprise Security Operations
An online shopping site restricts the quantity of an item each customer can order. The site generates the following code when the customer clicks the submit button. However, custom...
input validationclient-side controlsweb application securityHTTP interception - Question #946Enterprise Security Architecture
An extensive third-party audit reveals a number of weaknesses m a company's endpoint security posture. The most significant issues are as follows: Which of the following endpoint s...
endpoint securityDLPadvanced malware protectionmachine learning - Question #947Enterprise Security Operations
An analyst discovers the following while reviewing some recent activity logs: Which of the following tools would MOST likely identify a future incident in a timely manner?
file integrity monitoringincident detectionlog analysissecurity monitoring - Question #948Enterprise Security Operations
Company policy dictates that events from at least the past three months must be stored centrally for review. When a security incident occurs the security analyst investigates the u...
log managementcentralized logginglog retentionSIEM - Question #949Research, Development and Collaboration
A security engineer has received feedback from other security professionals about the effectiveness of hiding a wireless SSID as a security measure. Opinions vary as to whether thi...
wireless securitySSID hidingsecurity researchWiFi hardening - Question #950Risk Management
Company policy mandates the secure disposal of sensitive data at the end of the useful lifespan of IT equipment. The IT department donates old devices to charity and recycles truly...
data disposalmedia sanitizationasset managementSSD disposal - Question #951Enterprise Security Architecture
As a result of a recent breach a systems administrator is asked to review the security controls in place for an organization's cloud-based environment. The organization runs numero...
cloud securityMFAstaging environmentcredential harvesting - Question #952Enterprise Security Architecture
A company is planning to undergo a P2V project to improve resource utilisation redundancy, and failover across its two datacenters. A consultant has provided a private cloud design...
hypervisor securityremote attestationvirtualizationType 1 hypervisor - Question #953Risk Management
A software development company recently implemented a new policy and control ruleset. The control ruleset defines the following: - Account naming standards - Password complexity st...
compliance managementpolicy implementationremediation trackingrisk acceptance - Question #954Research, Development and Collaboration
A software company tripled its workforce by hiring numerous early career developers out of college. The senior development team has a long-running history of secure coring mostly t...
secure codingdeveloper trainingstatic analysisSDLC - Question #955Risk Management
Which of the following would MOST likely cause an organization to review and potentially rebaseline its current risk assessment?
risk assessmentrisk rebaselinethreat landscaperisk management - Question #956Technical Integration of Enterprise Security
A new identity management program was recently initialed to reduce risk and improve the employee experience. The environment is complex it does not support rest APIs but has multip...
identity federationOAuthSCIMSSO protocols - Question #957Enterprise Security Operations
A company's Chief Information Security Officer (CISO) is reviewing KPls from me security operations team. These KPls indicate the following trends: - The mean time to close securit...
SOC operationssecurity analyst tiersKPI analysissecurity metrics - Question #958Enterprise Security Operations
A security analyst discovers what is believed to be evidence of a compromise due to a watering- note attack. After an initial review of the incident the analyst notes there is ongo...
watering hole attackincident responsenetwork forensicstcpdump - Question #959Risk Management
Which of the following is the BEST way for a company to begin understanding product-based solutions to mitigate a known risk?
vendor managementprocurementRFIrisk mitigation - Question #960Enterprise Security Architecture
A security engineer is attempting to inventory all network devices Most unknown devices are not responsive to SNMP queries. Which of the following would be the MOST secure configur...
SNMPSNMPv3network device managementsecure configuration - Question #961Enterprise Security Operations
A security analyst is reviewing the logs from a NIDS. the analyst notices the following in quick succession between a client and a web server. Which of the following describes what...
protocol downgrade attackTLS/SSLNIDS analysisHSTS - Question #962Research, Development and Collaboration
A major OS vendor implements an IDE-integrated tool that alerts developers on the use of insecure and deprecated C code functions. Using which of the following functions would yiel...
secure codingbuffer overflowstrcpyC programming - Question #963Enterprise Security Operations
A manufacturing firm has multiple security appliances m production that were configured to log events but have not been maintained or tuned. A security engineer discovers multiple...
SIEM integrationlog managementsecurity appliancesalerting - Question #964Research, Development and Collaboration
Which of the following vulnerabilities did the analyst uncover?
buffer overflowsecure codingvulnerability analysisstrcpy - Question #965Enterprise Security Architecture
The credentials of a hospital's HVAC vendor were obtained using credential-harvesting malware through a phishing email. The HVAC vendor has administrative privileges m the SCADA ne...
SCADA securitycredential harvestingnetwork segmentationthird-party access - Question #966Enterprise Security Operations
An organization has hardened its end points m the following ways: - USB ports are disabled except for approved input device IDs (e.g, mouse, keyboard) - A desktop firewall is Mocki...
data loss preventionendpoint hardeningUSB securitydata exfiltration - Question #967Enterprise Security Operations
A penetration tester is trying to 9am access to a bulking after hours as part of a physical assessment of an office complex. The tester notes that each employee touches a badge nea...
physical securityRFIDpenetration testingbadge cloning - Question #968Risk Management
A security architect is called into a roadmap planning meeting for the next year of IT protects. One of the protects involves migrating from the current mobile, laptop, and tablet...
MDMBYODmobile privacycontainerization - Question #969Risk Management
A company has launched a phishing awareness campaign that includes serving customized phishing email to employees. Employees are encouraged to report all phishing attempts and/or d...
phishing awarenesssecurity metricsbenchmarkingsecurity awareness training - Question #970Risk Management
Which of the following is a major goal of stakeholder engagement?
stakeholder engagementsecurity governancebusiness alignmentsecurity requirements - Question #971Risk Management
A company is updating its acceptable use and security policies to allow personal devices to be connected to the network as king as certain security parameters can be enforced. Whic...
BYODmobile policyacceptable use policydevice management - Question #972Enterprise Security Architecture
A company wants to analyze internal network traffic for IOCs. The security solution consists of a network collector appliance and a separate server which security analysts access v...
network monitoring architecturetraffic analysisIOC detectionnetwork tap placement - Question #973Risk Management
A facilities manager requests approval to deploy a new key management system that integrates with logical network access controls to provide conditional access. The security analys...
risk assessmentvendor researchkey management systemsresearch methodology - Question #974Enterprise Security Operations
A security tester is performing a Mack-box assessment of an RFID access control system. The tester has a handful of RFID tags and is able to access the reader. However, the tester...
RFID penetration testingblack-box assessmentreplay attackaccess control testing - Question #1155Enterprise Security Operations
Over the last 90 days, many storage services has been exposed in the cloud services environments, and the security team does not have the ability to see is creating these instance....
shadow ITcloud visibilityCASBuser behavior analytics