CAS-003 Exam Question 116

An engineer is evaluating the control profile to assign to a system containing PII, financial, and proprietary data.

Based on the dataclassification table above, which of the following BEST describes the overall classification?
  • CAS-003 Exam Question 117

    An infrastructure team is at the end of a procurement process and has selected a vendor. As part of the final negotiations, there are a number of outstanding issues, including:
    1. Indemnity clauses have identified the maximum liability
    2. The data will be hosted and managed outside of the company's geographical location The number of users accessing the system will be small, and no sensitive data will be hosted in the solution. As the security consultant on the project, which of the following should the project's security consultant recommend as the NEXT step?
  • CAS-003 Exam Question 118

    A security architect is implementing security measures in response to an external audit that found vulnerabilities in the corporate collaboration tool suite. The report identified the lack of any mechanism to provide confidentiality for electronic correspondence between users and between users and group mailboxes. Which of the following controls would BEST mitigate the identified vulnerability?
  • CAS-003 Exam Question 119

    A request has been approved for a vendor to access a new internal server using only HTTPS and SSH to manage the back-end system for the portal. Internal users just need HTTP and HTTPS access to all internal web servers. All other external access to the new server and its subnet is not allowed. The security manager must ensure proper access is configured.

    Below is a snippet from the firewall related to that server (access is provided in a top-down model):

    Which of the following lines should be configured to allow the proper access? (Choose two.)
  • CAS-003 Exam Question 120

    A new piece of ransomware got installed on a company's backup server which encrypted the hard drives containing the OS and backup application configuration but did not affect the deduplication data hard drives. During the incident response, the company finds that all backup tapes for this server are also corrupt. Which of the following is the PRIMARY concern?