REAL COMPTIA CYSA+ CAS-003 EXAM
QUESTIONS V13.02 | KILLTEST
AnEinfrastructureEteamEisEatEtheEendEofEaEprocurementEprocessEandEhasEselectedEaEvendor.EAsEpartE
ofEtheEfinalEnegotiations,EthereEareEaEnumberEofEoutstandingEissues,Eincluding:
IndemnityEclausesEhaveEidentifiedEtheEmaximumEliability
TheEdataEwillEbeEhostedEandEmanagedEoutsideEofEtheEcompany'sEgeographicalElocationETheEnumbe
rEofEusersEaccessingEtheEsystemEwillEbeEsmall,EandEnoEsensitiveEdataEwillEbeEhostedEinEtheEsolution.
AsEtheEsecurityEconsultantEonEtheEproject,EwhichEofEtheEfollowingEshouldEtheEproject'sEsecurityEcon
sultantErecommendEasEtheENEXTEstep?
A.EDevelopEaEsecurityEexemption,EasEitEdoesEnotEmeetEtheEsecurityEpolicies
B.EMitigateEtheEriskEbyEaskingEtheEvendorEtoEacceptEtheEin-countryEprivacyEprinciples
C.ERequireEtheEsolutionEownerEtoEacceptEtheEidentifiedErisksEandEconsequences
D.EReviewEtheEentireEprocurementEprocessEtoEdetermineEtheElessonsElearnedE-
ECORRECTEANSWERC.ERequireEtheEsolutionEownerEtoEacceptEtheEidentifiedErisksEandEconsequence
s
AEcompanyEhasEenteredEintoEaEbusinessEagreementEwithEaEbusinessEpartnerEforEmanagedEhumanEr
esourcesEservices.ETheEChiefEInformationESecurityEOfficerE(CISO)EhasEbeenEaskedEtoEprovideEdocu
mentationEthatEisErequiredEtoEsetEupEaEbusiness-to-businessEVPNEbetweenEtheEtwoEorganizations.
WhichEofEtheEfollowingEisErequiredEinEthisEscenario?
A.EISA
B.EBIA
C.ESLA
D.ERAE-ECORRECTEANSWERA.EISA
AnESQLEdatabaseEisEnoElongerEaccessibleEonlineEdueEtoEaErecentEsecurityEbreach.EAnEinvestigationEr
evealsEthatEunauthorizedEaccessEtoEtheEdatabaseEwasEpossibleEdueEtoEanESQLEinjectionEvulnerabilit
y.
, ToEpreventEthisEtypeEofEbreachEinEtheEfuture,EwhichEofEtheEfollowingEsecurityEcontrolsEshouldEbeEpu
tEinEplaceEbeforeEbringingEtheEdatabaseEbackEonline?E(ChooseEtwo.)
A.ESecureEstorageEpolicies
B.EBrowserEsecurityEupdates
C.EInputEvalidation
D.EWebEapplicationEfirewall
E.ESecureEcodingEstandards
F.EDatabaseEactivityEmonitoringE-ECORRECTEANSWERC.EInputEvalidation
F.EDatabaseEactivityEmonitoring
AEsecurityEadministratorEisEhardeningEaETrustedSolarisEserverEthatEprocessesEsensitiveEdata.
TheEdataEownerEhasEestablishedEtheEfollowingEsecurityErequirements:
-ETheEdataEisEforEinternalEconsumptionEonlyEandEshallEnotEbeEdistributedEtoEoutsideEindividuals
-ETheEsystemsEadministratorEshouldEnotEhaveEaccessEtoEtheEdataEprocessedEbyEtheEserver
-ETheEintegrityEofEtheEkernelEimageEisEmaintained
WhichEofEtheEfollowingEhost-
basedEsecurityEcontrolsEBESTEenforceEtheEdataEowner'sErequirements?E(ChooseEthree.)
A.ESELinux
B.EDLP
C.EHIDS
D.EHost-basedEfirewall
E.EMeasuredEboot
F.EDataEencryption
G.EWatermarkingE-ECORRECTEANSWERC.EHIDS
E.EMeasuredEboot
F.EDataEencryption
QUESTIONS V13.02 | KILLTEST
AnEinfrastructureEteamEisEatEtheEendEofEaEprocurementEprocessEandEhasEselectedEaEvendor.EAsEpartE
ofEtheEfinalEnegotiations,EthereEareEaEnumberEofEoutstandingEissues,Eincluding:
IndemnityEclausesEhaveEidentifiedEtheEmaximumEliability
TheEdataEwillEbeEhostedEandEmanagedEoutsideEofEtheEcompany'sEgeographicalElocationETheEnumbe
rEofEusersEaccessingEtheEsystemEwillEbeEsmall,EandEnoEsensitiveEdataEwillEbeEhostedEinEtheEsolution.
AsEtheEsecurityEconsultantEonEtheEproject,EwhichEofEtheEfollowingEshouldEtheEproject'sEsecurityEcon
sultantErecommendEasEtheENEXTEstep?
A.EDevelopEaEsecurityEexemption,EasEitEdoesEnotEmeetEtheEsecurityEpolicies
B.EMitigateEtheEriskEbyEaskingEtheEvendorEtoEacceptEtheEin-countryEprivacyEprinciples
C.ERequireEtheEsolutionEownerEtoEacceptEtheEidentifiedErisksEandEconsequences
D.EReviewEtheEentireEprocurementEprocessEtoEdetermineEtheElessonsElearnedE-
ECORRECTEANSWERC.ERequireEtheEsolutionEownerEtoEacceptEtheEidentifiedErisksEandEconsequence
s
AEcompanyEhasEenteredEintoEaEbusinessEagreementEwithEaEbusinessEpartnerEforEmanagedEhumanEr
esourcesEservices.ETheEChiefEInformationESecurityEOfficerE(CISO)EhasEbeenEaskedEtoEprovideEdocu
mentationEthatEisErequiredEtoEsetEupEaEbusiness-to-businessEVPNEbetweenEtheEtwoEorganizations.
WhichEofEtheEfollowingEisErequiredEinEthisEscenario?
A.EISA
B.EBIA
C.ESLA
D.ERAE-ECORRECTEANSWERA.EISA
AnESQLEdatabaseEisEnoElongerEaccessibleEonlineEdueEtoEaErecentEsecurityEbreach.EAnEinvestigationEr
evealsEthatEunauthorizedEaccessEtoEtheEdatabaseEwasEpossibleEdueEtoEanESQLEinjectionEvulnerabilit
y.
, ToEpreventEthisEtypeEofEbreachEinEtheEfuture,EwhichEofEtheEfollowingEsecurityEcontrolsEshouldEbeEpu
tEinEplaceEbeforeEbringingEtheEdatabaseEbackEonline?E(ChooseEtwo.)
A.ESecureEstorageEpolicies
B.EBrowserEsecurityEupdates
C.EInputEvalidation
D.EWebEapplicationEfirewall
E.ESecureEcodingEstandards
F.EDatabaseEactivityEmonitoringE-ECORRECTEANSWERC.EInputEvalidation
F.EDatabaseEactivityEmonitoring
AEsecurityEadministratorEisEhardeningEaETrustedSolarisEserverEthatEprocessesEsensitiveEdata.
TheEdataEownerEhasEestablishedEtheEfollowingEsecurityErequirements:
-ETheEdataEisEforEinternalEconsumptionEonlyEandEshallEnotEbeEdistributedEtoEoutsideEindividuals
-ETheEsystemsEadministratorEshouldEnotEhaveEaccessEtoEtheEdataEprocessedEbyEtheEserver
-ETheEintegrityEofEtheEkernelEimageEisEmaintained
WhichEofEtheEfollowingEhost-
basedEsecurityEcontrolsEBESTEenforceEtheEdataEowner'sErequirements?E(ChooseEthree.)
A.ESELinux
B.EDLP
C.EHIDS
D.EHost-basedEfirewall
E.EMeasuredEboot
F.EDataEencryption
G.EWatermarkingE-ECORRECTEANSWERC.EHIDS
E.EMeasuredEboot
F.EDataEencryption