CAS-003 Exam Question 216

The IT Security Analyst for a small organization is working on a customer's system and identifies a possible intrusion in a database that contains PII. Since PII is involved, the analyst wants to get the issue addressed as soon as possible. Which of the following is the FIRST step the analyst should take in mitigating the impact of the potential intrusion?
  • CAS-003 Exam Question 217

    As a result of an acquisition, a new development team is being integrated into the company. The development team has BYOD laptops with IDEs installed, build servers, and code repositories that utilize SaaS. To have the team up and running effectively, a separate Internet connection has been procured.
    A stand up has identified the following additional requirements:
    1. Reuse of the existing network infrastructure
    2. Acceptable use policies to be enforced
    3. Protection of sensitive files
    4. Access to the corporate applications
    Which of the following solution components should be deployed to BEST meet the requirements? (Choose three.)
  • CAS-003 Exam Question 218

    A breach was caused by an insider threat in which customer PII was compromised.
    Following the breach, a lead security analyst is asked to determine which vulnerabilities the attacker used to access company resources. Which of the following should the analyst use to remediate the vulnerabilities?
  • CAS-003 Exam Question 219

    The helpdesk is receiving multiple calls about slow and intermittent Internet access from the finance department. The following information is compiled:
    Caller 1, IP 172.16.35.217, NETMASK 255.255.254.0
    Caller 2, IP 172.16.35.53, NETMASK 255.255.254.0
    Caller 3, IP 172.16.35.173, NETMASK 255.255.254.0
    All callers are connected to the same switch and are routed by a router with five built-in interfaces. The upstream router interface's MAC is 00-01-42-32-ab-1a A packet capture shows the following:
    09:05:15.934840 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a
    (00:01:42:32:ab:1a)
    09:06:16.124850 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a
    (00:01:42:32:ab:1a)
    09:07:25.439811 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a
    (00:01:42:32:ab:1a)
    09:08:10.937590 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id
    2305, seq 1, length 65534
    09:08:10.937591 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id
    2306, seq 2, length 65534
    09:08:10.937592 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id
    2307, seq 3, length 65534
    Which of the following is occurring on the network?
  • CAS-003 Exam Question 220

    A network engineer is upgrading the network perimeter and installing a new firewall, IDS, and external edge router. The IDS is reporting elevated UDP traffic, and the internal routers are reporting high utilization. Which of the following is the BEST solution?