CAS-003 Exam Question 6

A company has noticed recently that its corporate information has ended up on an online forum. An investigation has identified that internal employees are sharing confidential corporate information on a daily basis. Which of the following are the MOST effective security controls that can be implemented to stop the above problem? (Select TWO).
  • CAS-003 Exam Question 7

    A developer emails the following output to a security administrator for review:

    Which of the following tools might the security administrator use to perform further security assessment of this issue?
  • CAS-003 Exam Question 8

    The government is concerned with remote military missions being negatively being impacted by the use of technology that may fail to protect operational security. To remediate this concern, a number of solutions have been implemented, including the following:
    * End-to-end encryption of all inbound and outbound communication, including personal email and chat sessions that allow soldiers to securely communicate with families.
    * Layer 7 inspection and TCP/UDP port restriction, including firewall rules to only allow TCP port 80 and
    443 and approved applications
    * A host-based whitelist of approved websites and applications that only allow mission-related tools and sites
    * The use of satellite communication to include multiple proxy servers to scramble the source IP address Which of the following is of MOST concern in this scenario?
  • CAS-003 Exam Question 9

    An organization is currently working with a client to migrate data between a legacy ERP system and a cloud- based ERP tool using a global PaaS provider. As part of the engagement, the organization is performing data deduplication and sanitization of client data to ensure compliance with regulatory requirements. Which of the following is the MOST likely reason for the need to sanitize the client data?
  • CAS-003 Exam Question 10

    The Chief Information Security Officer (CISO) of an established security department, identifies a customer who has been using a fraudulent credit card. The CISO calls the local authorities, and when they arrive on-site, the authorities ask a security engineer to create a point-in-time copy of the running database in their presence. This is an example of: