CAS-003 Exam Question 51

A project manager is working with a software development group to collect and evaluate user stories related to the organization's internally designed CRM tool. After defining requirements, the project manager would like to validate the developer's interpretation and understanding of the user's request. Which of the following would BEST support this objective?
  • CAS-003 Exam Question 52

    A company suspects a web server may have been infiltrated by a rival corporation. The security engineer reviews the web server logs and finds the following:

    The security engineer looks at the code with a developer, and they determine the log entry is created when the following line is run:

    Which of the following is an appropriate security control the company should implement?
  • CAS-003 Exam Question 53

    A security engineer is working on a large software development project. As part of the design of the project, various stakeholder requirements were gathered and decomposed to an implementable and testable level.
    Various security requirements were also documented.
    Organize the following security requirements into the correct hierarchy required for an SRTM.
    Requirement 1: The system shall provide confidentiality for data in transit and data at rest.
    Requirement 2: The system shall use SSL, SSH, or SCP for all data transport.
    Requirement 3: The system shall implement a file-level encryption scheme.
    Requirement 4: The system shall provide integrity for all data at rest.
    Requirement 5: The system shall perform CRC checks on all files.
  • CAS-003 Exam Question 54

    The risk subcommittee of a corporate board typically maintains a master register of the most prominent
    risks to the company. A centralized holistic view of risk is particularly important to the corporate Chief
    Information Security Officer (CISO) because:
  • CAS-003 Exam Question 55

    Customers are receiving emails containing a link to malicious software. These emails are subverting spam filters. The email reads as follows:
    Delivered-To: [email protected]
    Received: by 10.14.120.205
    Mon, 1 Nov 2010 11:15:24 -0700 (PDT)
    Received: by 10.231.31.193
    Mon, 01 Nov 2010 11:15:23 -0700 (PDT)
    Return-Path: <[email protected]>
    Received: from 127.0.0.1 for <[email protected]>; Mon, 1 Nov 2010 13:15:14 -0500 (envelope-from <[email protected]>) Received: by smtpex.example.com (SMTP READY) with ESMTP (AIO); Mon, 01 Nov 2010 13:15:14 -0500 Received: from 172.18.45.122 by 192.168.2.55; Mon, 1 Nov 2010 13:15:14 -0500 From: Company <[email protected]> To: "[email protected]" <[email protected]> Date: Mon, 1 Nov 2010 13:15:11 -0500 Subject: New Insurance Application Thread-Topic: New Insurance Application Please download and install software from the site below to maintain full access to your account.
    www.examplesite.com
    ________________________________
    Additional information: The authorized mail servers IPs are 192.168.2.10 and 192.168.2.11.
    The network's subnet is 192.168.2.0/25.
    Which of the following are the MOST appropriate courses of action a security administrator could take to eliminate this risk? (Select TWO).