CAS-003 문제 126

CIO(최고 정보 책임자)는 관련 지표가 포함된 보안 대시보드를 개발하라는 요청을 받았습니다. 이사회는 대시보드를 사용하여 조직의 전반적인 보안 상태를 모니터링하고 추적합니다. CIO는 이사회가 검토할 수 있도록 두 개의 별도 섹션에 KPI와 KRI 데이터를 모두 포함하는 기본 보고서를 생성합니다.
다음 중 이사회의 요구 사항을 가장 잘 충족하는 것은 무엇입니까?

CAS-003 문제 127

An information security manager is concerned that connectivity used to configure and troubleshoot critical
network devices could be attacked. The manager has tasked a network security engineer with meeting the
following requirements:
Encrypt all traffic between the network engineer and critical devices.

Segregate the different networking planes as much as possible.

Do not let access ports impact configuration tasks.

Which of the following would be the BEST recommendation for the network security engineer to present?

CAS-003 문제 128

A critical system audit shows that the payroll system is not meeting security policy due to missing OS security patches. Upon further review, it appears that the system is not being patched at all. The vendor states that the system is only supported on the current OS patch level. Which of the following compensating controls should be used to mitigate the vulnerability of missing OS patches on this system?

CAS-003 문제 129

A company has gone through a round of phishing attacks. More than 200 users have had their workstation infected because they clicked on a link in an email. An incident analysis has determined an executable ran and compromised the administrator account on each workstation. Management is demanding the information security team prevent this from happening again.
Which of the following would BEST prevent this from happening again?

CAS-003 문제 130

Which of the following describes a risk and mitigation associated with cloud data storage?