CAS-003 Exam Question 131

The Chief Executive Officer (CEO) of a company has considered implementing a cost-saving measure that might result in new risk to the company. When deciding whether to implement this measure, which of the following would be the BEST course of action to manage the organization's risk?
  • CAS-003 Exam Question 132

    A forensic analyst receives a hard drive containing malware quarantined by the antivirus application. After creating an image and determining the directory location of the malware file, which of the following helps to determine when the system became infected?
  • CAS-003 Exam Question 133

    Customers are receiving emails containing a link to malicious software. These emails are subverting spam filters. The email reads as follows:
    Delivered-To: [email protected]
    Received: by 10.14.120.205
    Mon, 1 Nov 2010 11:15:24 -0700 (PDT)
    Received: by 10.231.31.193
    Mon, 01 Nov 2010 11:15:23 -0700 (PDT)
    Return-Path: <[email protected]>
    Received: from 127.0.0.1 for <[email protected]>; Mon, 1 Nov 2010 13:15:14 -0500 (envelope-from <[email protected]>) Received: by smtpex.example.com (SMTP READY) with ESMTP (AIO); Mon, 01 Nov 2010 13:15:14 -0500 Received: from 172.18.45.122 by 192.168.2.55; Mon, 1 Nov 2010 13:15:14 -0500 From: Company <[email protected]> To: "[email protected]" <[email protected]> Date: Mon, 1 Nov 2010 13:15:11 -0500 Subject: New Insurance Application Thread-Topic: New Insurance Application Please download and install software from the site below to maintain full access to your account.
    www.examplesite.com
    ________________________________
    Additional information: The authorized mail servers IPs are 192.168.2.10 and 192.168.2.11.
    The network's subnet is 192.168.2.0/25.
    Which of the following are the MOST appropriate courses of action a security administrator could take to eliminate this risk? (Select TWO).
  • CAS-003 Exam Question 134

    An administrator has enabled salting for users' passwords on a UNIX box. A penetration tester must attempt to retrieve password hashes. Which of the following files must the penetration tester use to eventually obtain passwords on the system? (Select TWO).
  • CAS-003 Exam Question 135

    During a recent incident, sensitive data was disclosed and subsequently destroyed through a properly secured, cloud-based storage platform. An incident response technician is working with management to develop an after action report that conveys critical metrics regarding the incident.
    Which of the following would be MOST important to senior leadership to determine the impact of the breach?