CASP Practice Exam 3 2023 with 100% correct answers
You are the security administrator for your company. You are required to implement a solution that will provide the highest level of confidentiality possible to all data on the network. Two-factor token and biometric-based authentication is implemented for all users. Administrator-level accounts are tightly controlled and issued separately to each user needing administrative access. Auditing is enabled to log all transactions. All hard drives are protected using full disk encryption. All resources have access control lists (ACLs) that can only be changed by an administrator. All server resources are virtualized. LUN masking is implemented to segregate storage area network (SAN) data. All switches are configured with port security. The network is protected with a firewall using ACLs, a NIPS device, and secured wireless access points. You need to improve the current architecture to provide the stated goal. What should you do? Options: A. Implement transport encryption. B. Implement MAC filtering on all network devices. C. Implement data-at-rest encryption. D. Implement PKI authorization. Answer: A Explanation: You should implement transport encryption to provide the highest level of confidentiality possible for all data on the network. The public relations department at your company regularly sends out emails signed by the company's CEO with announcements about the company. The CEO sends company and personal emails from a different email account. A competitor is suing your company for copyright infringement. As part of the investigation, you must provide legal counsel with a copy of all emails that came from the CEO, including those generated by the public relations department. The email server allows emails to be digitally signed, and the corporate PKI provisioning allows for one certificate per user. The CEO did not share his password with anyone. You need to provide legal counsel with information on how to determine whether a particular email came from the public relations department or from the CEO. What should you do? Options: A. Implement digital rights management (DRM). B. Use non-repudiation. C. Implement encryption. D. Employ key escrow. Answer: B Explanation: You should use non-repudiation. Non-repudiation is provided when an email includes a digital signature.
Información del documento
- Subido en
- 15 de julio de 2023
- Número de páginas
- 52
- Escrito en
- 2022/2023
- Tipo
- Examen
- Contiene
- Preguntas y respuestas