CAS-003 Exam Question 16

A company decides to purchase commercially available software packages. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?
  • CAS-003 Exam Question 17

    An administrator has noticed mobile devices from an adjacent company on the corporate wireless network.
    Malicious activity is being reported from those devices. To add another layer of security in an enterprise environment, an administrator wants to add contextual authentication to allow users to access enterprise resources only while present in corporate buildings. Which of the following technologies would accomplish this?
  • CAS-003 Exam Question 18

    Executive management is asking for a new manufacturing control and workflow automation solution. This application will facilitate management of proprietary information and closely guarded corporate trade secrets.
    The information security team has been a part of the department meetings and come away with the following notes:
    Human resources would like complete access to employee data stored in the application. They would like automated data interchange with the employee management application, a cloud- based SaaS application.
    Sales is asking for easy order tracking to facilitate feedback to customers.
    Legal is asking for adequate safeguards to protect trade secrets. They are also concerned with data ownership questions and legal jurisdiction.
    Manufacturing is asking for ease of use. Employees working the assembly line cannot be bothered with additional steps or overhead. System interaction needs to be quick and easy.
    Quality assurance is concerned about managing the end product and tracking overall performance of the product being produced. They would like read-only access to the entire workflow process for monitoring and baselining.
    The favored solution is a user friendly software application that would be hosted onsite. It has extensive ACL functionality, but also has readily available APIs for extensibility. It supports read- only access, kiosk automation, custom fields, and data encryption.
    Which of the following departments' request is in contrast to the favored solution?
  • CAS-003 Exam Question 19

    A company recently deployed an agent-based DLP solution to all laptop in the environment. The DLP solution is configured to restrict the following:
    * USB ports
    * FTP connections
    * Access to cloud-based storage sites
    * Outgoing email attachments
    * Saving data on the local C: drive
    Despite these restrictions, highly confidential data was from a secure fileshare in the research department. Which of the following should the security team implement FIRST?
  • CAS-003 Exam Question 20

    Company A has noticed abnormal behavior targeting their SQL server on the network from a rogue IP address.
    The company uses the following internal IP address ranges: 192.10.1.0/24 for the corporate site and
    192.10.2.0/24 for the remote site. The Telco router interface uses the 192.10.5.0/30 IP range.
    Instructions: Click on the simulation button to refer to the Network Diagram for Company A.
    Click on Router 1, Router 2, and the Firewall to evaluate and configure each device.
    Task 1: Display and examine the logs and status of Router 1, Router 2, and Firewall interfaces.
    Task 2: Reconfigure the appropriate devices to prevent the attacks from continuing to target the SQL server and other servers on the corporate network.