CAS-003 Exam Question 201

An organization is attempting to harden its web servers and reduce the information that might be disclosed by potential attackers. A security anal... reviewing vulnerability scan result from a recent web server scan.
Portions of the scan results are shown below:
Finding# 5144322
First time detected 10 nov 2015 09:00 GMT_0600
Last time detected 10 nov 2015 09:00 GMT_0600
CVSS base: 5
Access path: http://myorg.com/mailinglist.htm
Request: GET http://mailinglist.aspx?content=volunteer
Response: C:\Docments\MarySmith\malinglist.pdf
Which of the following lines indicates information disclosure about the host that needs to be remediated?
  • CAS-003 Exam Question 202

    A security administrator was doing a packet capture and noticed a system communicating with an unauthorized address within the 2001::/32 prefix. The network administrator confirms there is no IPv6 routing into or out of the network.
    Which of the following is the BEST course of action?
  • CAS-003 Exam Question 203

    Company policy requires that all company laptops meet the following baseline requirements:
    Software requirements:
    Antivirus
    Anti-malware
    Anti-spyware
    Log monitoring
    Full-disk encryption
    Terminal services enabled for RDP
    Administrative access for local users
    Hardware restrictions:
    Bluetooth disabled
    FireWire disabled
    WiFi adapter disabled
    Ann, a web developer, reports performance issues with her laptop and is not able to access any network resources. After further investigation, a bootkit was discovered and it was trying to access external websites.
    Which of the following hardening techniques should be applied to mitigate this specific issue from reoccurring? (Select TWO).
  • CAS-003 Exam Question 204

    Which of the following technologies prevents an unauthorized HBA fromviewing iSCSI target information?
  • CAS-003 Exam Question 205

    An organization is currently performing a market scan for managed security services and EDR capability. Which of the following business documents should be released to the prospective vendors in the first step of the process? (Select TWO).