• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 52 pages
Exam (elaborations)

CASP 4 UPDATED ACTUAL Exam Questions and CORRECT Answers

Document preview thumbnail
Preview 4 out of 52 pages

CASP 4 UPDATED ACTUAL Exam Questions and CORRECT Answers The internal audit department is investigating a possible breach of security. One of the auditors is sent to interview the following employees: Employee A. Works in the accounts receivable office and is in charge of entering data into the finance system. Employee B. Works in the accounts payable office and is in charge of approving purchase orders. Employee C. Is the manager of the finance department, supervises Employee A and Employee B, and can perform the functions of both Employee A and Employee B. Which of the following should the auditor suggest be done to avoid future security breaches?

Content preview

CASP 4 UPDATED ACTUAL Exam
Questions and CORRECT Answers
The internal audit department is investigating a possible breach of security. One of the auditors is
sent to interview the following employees:
Employee A. Works in the accounts receivable office and is in charge of entering data into the
finance system.
Employee B. Works in the accounts payable office and is in charge of approving purchase
orders.
Employee C. Is the manager of the finance department, supervises Employee A and Employee B,
and can perform the functions of both Employee A and Employee B.
Which of the following should the auditor suggest be done to avoid future security breaches?


A. All employees should have the same access level to be able to check on each others.
B. The manager should only be able to review the data and approve purchase orders.
C. Employee A and Employee B should rotate jobs at a set interval and cross-train.
D. The manager should be able to both enter and approve information. - CORRECT
ANSWER - B. The manager should only be able to review the data and approve purchase
orders.


A company's security policy states that its own internally developed proprietary Internet facing
software must be resistant to web application attacks. Which of the following methods provides
the
MOST protection against unauthorized access to stored database information?


A. Require all development to follow secure coding practices.
B. Require client-side input filtering on all modifiable fields.
C. Escape character sequences at the application tier.

D. Deploy a WAF with application specific signatures. - CORRECT ANSWER - A.
Require all development to follow secure coding practices.

,An organization is preparing to upgrade its firewall and NIPS infrastructure and has narrowed
the
vendor choices down to two platforms. The integrator chosen to assist the organization with the
deployment has many clients running a mixture of the possible combinations of environments.
Which of the following is the MOST comprehensive method for evaluating the two platforms?


A. Benchmark each possible solution with the integrators existing client deployments.
B. Develop testing criteria and evaluate each environment in-house.
C. Run virtual test scenarios to validate the potential solutions.
D. Use results from each vendor's test labs to determine adherence to project requirements. -
CORRECT ANSWER - B. Develop testing criteria and evaluate each environment in-
house.


An administrator has four virtual guests on a host server. Two of the servers are corporate SQL
servers, one is a corporate mail server, and one is a testing web server for a small group of
developers. The administrator is experiencing difficulty connecting to the host server during
peak
network usage times. Which of the following would allow the administrator to securely connect
to
and manage the host server during peak usage times?


A. Increase the virtual RAM allocation to high I/O servers.
B. Install a management NIC and dedicated virtual switch.
C. Configure the high I/O virtual servers to use FCoE rather than iSCSI.

D. Move the guest web server to another dedicated host. - CORRECT ANSWER - B.
Install a management NIC and dedicated virtual switch.


An administrator receives a notification from legal that an investigation is being performed on
members of the finance department. As a precaution, legal has advised a legal hold on all

,documents for an unspecified period of time. Which of the following policies will MOST likely
be
violated? (Select TWO).


A. Data Storage Policy
B. Data Retention Policy
C. Corporate Confidentiality Policy
D. Data Breach Mitigation Policy

E. Corporate Privacy Policy - CORRECT ANSWER - A. Data Storage Policy
B. Data Retention Policy


Which of the following BEST explains SAML?


A. A security attestation model built on XML and SOAP-based services, which allows for the
exchange of A&A data between systems and supports Federated Identity Management.
B. An XML and SOAP-based protocol, which enables the use of PKI for code signing and SSO
by
using SSL and SSH to establish a trust model.
C. A security model built on the transfer of assertions over XML and SOAP-based protocols,
which
allows for seamless SSO and the open exchange of data.
D. A security verification model built on SSO and SSL-based services, which allows for the

exchange of PKI data between users and supports XACML. - CORRECT ANSWER - A.
A security attestation model built on XML and SOAP-based services, which allows for the
exchange of A&A data between systems and supports Federated Identity Management.


The organization has an IT driver on cloud computing to improve delivery times for IT solution
provisioning. Separate to this initiative, a business case has been approved for replacing the
existing banking platform for credit card processing with a newer offering. It is the security

, practitioner's responsibility to evaluate whether the new credit card processing platform can be
hosted within a cloud environment. Which of the following BEST balances the security risk and
IT
drivers for cloud computing?


A. A third-party cloud computing platform makes sense for new IT solutions. This should be
endorsed going forward so as to align with the IT strategy. However, the security practitioner
will
need to ensure that the third-party cloud provider does regular penetration tests to ensure that all
data is secure.
B. Using a third-party cloud computing environment should be endorsed going forward. This
aligns

with the organiz - CORRECT ANSWER - C. There may be regulatory restrictions with
credit cards being processed out of country or
processed by shared hosting providers. A private cloud within the company should be
considered.
An options paper should be created which outlines the risks, advantages, disadvantages of
relevant choices and it should recommended a way forward.


The Universal Research Association has just been acquired by the Association of Medical
Business Researchers. The new conglomerate has funds to upgrade or replace hardware as part
of the acquisition, but cannot fund labor for major software projects. Which of the following will
MOST likely result in some IT resources not being integrated?


A. One of the companies may use an outdated VDI.
B. Corporate websites may be optimized for different web browsers.
C. Industry security standards and regulations may be in conflict.
D. Data loss prevention standards in one company may be less stringent. - CORRECT
ANSWER - C. Industry security standards and regulations may be in conflict.

Document information

Uploaded on
June 24, 2025
Number of pages
52
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$14.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STANFORDGRADESS
4.0
(240)
Sold
1653
Followers
108
Items
119940
Last sold
1 hour ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions