Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 8 pages
Exam (elaborations)

FedVTE CASP|2023 LATEST UPDATE|GUARANTEED SUCCESS

Document preview thumbnail
Preview 2 out of 8 pages

A flaw in an online sporting goods website allows customers to purchase multiple quantities of goods and only be charged the single quantity price. To improve the site, management is demanding that the ecommerce application be tested to insure this flaw is corrected. Which of the following is the BEST combination of tools and or methods to use? A. Blackbox testing using outside consultants C. Fuzzer and HTTP interceptor All adverse impacts of a security event can be measured quantitatively? False An activepassive cluster of redundant routers and firewalls has been installed in the network edge by your enterprise LAN/WAN engineer. The firewalls are using stateful firewall inspection. Even with the redundant equipment, there are still multiple reports of dropped connections with external clients. Which of the following is MOST likely the cause of this problem? TCP sessions are being rejected because they are being handled by asynchronous route paths through the firewalls. Which of the following describes a single sign on implementation? A web access load balancer passes the same authentication attributes in a HTTP header to multiple applications. What does the access control term AAA stand for? Authentication, Authorization, Accounting A government agency has a major new initiative to virtualize as many servers as possible, due to power and rack space capacity at its two data centers. The agency has prioritized virtualizing older servers first as the hardware is nearing end of life. The two initial migrations include Windows 2000 hosts (domain controllers and front-facing web servers) and open source Linux hosts (front facing web servers). Which of the following should occur based on best practices? Each data center should contain separate virtual environments for the web servers and for the domain controllers. Shifting the responsibility for a risk to a third party is which strategy for managing risks? Transfer Audit logs can be used to prevent users from performing unauthorized operations. False The CISO at a software development company is concerned about weaknesses in the review processes his company has for their major product. Testing was performed in house by a small review team, and the previous projects have been found to have that only limited test cases were used and many of the code paths remained untested. The CISO raised concerns that this product cannot fail in an upcoming large scale deployment. Which of the following will provide the MOST thorough additional testing? Run a small pilot test at the customers site before rolling out the complete deployment. Which of the following is the process of determining whether someone or something is who or what it declares itself to be? Authentication Which of the following is an incremental update between service packs or versions to fix outstanding issues? Maintenance release A new IDS appliance is generating a very large number of events, most of which are not security-related. Select the approach which best resolves this issue. Adjust IDS filters that are creating false positives. Which recovery site is fully equipped and is capable of restoring data and configurations within hours? B. Hot Site C. Mirrored Site Which of the following is the best choice for ensuring continuous availability? Redundancy A retail merchant has had a number of issues in regards to the integrity of sensitive information across all of its customer databases. This has resulted in the merchants share price decreasing in value by more than one third and the merchant has been threatened with losing their ability to process credit card transactions. The new Chief Information Security Officer (CISO) as a result has initiated a program of work to solve the issues. The business has specified that the solution needs to be enterprise grade and meet the following requirements: Work across all major platforms, applications and infrastructure; Tracks activity of all users, including administrators; Operates without negatively impacting the performance of production platforms, applications, and infrastructures; Provides real-time incident reporting; Displays incidents in a dashboard view for easy recognition; Includes a report generator where business units are able to query against companys system assets. In order to solve this problem, which of the following security solutions will BEST meet the above requirements? (Select TWO). A. Implement a security operations center to provide in depth analysis and incident response with periodic reporting capability. B. Implement an enterprise-based SIEM solution to process the logs of the major platforms, applications, and infrastructure. C. Implement a security operations center for real time monitoring and incident response and an event correlation dashboard with self service reporting capability. D. Ensure the NOC provides real time monitoring and incident response and an event correlation dashboard with self service reporting capabilities. E. Implement an agent only based SIEM solution to be deployed on all major platforms, applications, and infrastructures. F. Manually pull the logs from the major platforms, applications, and infrastructures to a central analysis center. C & E is wrong A medical group is converting to cloud computing to improve delivery times for IT solution adoption. The accounting department has made a case for replacing the existing banking platform for credit card processing with a newer offering. It is the security departments responsibility to evaluate whether the new credit card processing platform can be hosted within a cloud environment. Which of the following BEST balances the security risk and IT drivers for cloud computing? There may be regulatory restrictions with credit cards being processed out of country or processed by shared hosting providers. A private cloud within the company should be considered. An decision paper should be written to outline the risks, advantages and disadvantages of the options. A contractor is hired to assist in the development of a new application. Which of the following would you use to ensure the contractor does not share information about the project they worked on outside of the company? Non-Disclosure Agreement, NDA A companys security policy states that its internally developed proprietary Internet facing software must be resistant to web application attacks. Which of the following methods provides the MOST protection against unauthorized access to stored database information? Require all developers to follow secure coding practices. A Security Manager is selecting web conferencing systems for internal use. The system will only be used for internal employee collaboration. Which of the following should be the priority issues for the security manager? (Select THREE). Security of data storage System availability User authentication strategy The CISO regularly receives reports of a department repeatedly violating the corporate security policy. The head of the department informs the CISO that the offending behaviors are a result of necessary business activities. The CISO assigns a security administrator to find a solution for the issue. Which of the following is the BEST course of action for the security administrator to take? Draft an MOU for the department head and CISO to approve, documenting the limits of the necessary behaviour, and actions to be taken by both teams. An electrical utility has employed a consultant to perform a controls assessment of the personnel system, backend business operations, and the SCADA system used in their facility. Which of the following correctly states the risk management options that the consultant should use during the assessment? B. Avoid, transfer, mitigate, and accept. D. Calculate risk by determining technical likelihood and potential business impact. A company has implemented data retention policies and storage quotas in response to their legal departments requests and the SAN administrators recommendation. The retention policy states all email data older than 120 days should be eliminated. As there are no technical controls in place, users have been instructed to stick to a storage quota of 750Mb of network storage and 500Mb of email storage. After being presented with an ediscovery request from an opposing legal council, the security administrator discovers that the user in the suit has 1Tb of files and 800Mb of email spanning over two years. Which of the following should the security administrator provide to opposing council? Provide all available data regardless of age.


Document information

Uploaded on
June 19, 2023
Number of pages
8
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
GUARANTEEDSUCCESS
4.3
(253)
Sold
689
Followers
314
Items
24876
Last sold
6 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions

Whoops! We can’t load your doc right now. Try again or contact support.