CAS-003 문제 271
Which of the following BEST explains SAML?
CAS-003 문제 272
A business is growing and starting to branch out into other locations. In anticipation of opening an office in a different country, the Chief Information Security Officer (CISO) and legal team agree they need to meet the following criteria regarding data to open the new office:
* Store taxation-related documents for five years
* Store customer addresses in an encrypted format
* Destroy customer information after one year
* Keep data only in the customer's home country
Which of the following should the CISO implement to BEST meet these requirements? (Choose three.)
* Store taxation-related documents for five years
* Store customer addresses in an encrypted format
* Destroy customer information after one year
* Keep data only in the customer's home country
Which of the following should the CISO implement to BEST meet these requirements? (Choose three.)
CAS-003 문제 273
보안 관리자는 외부 소스에서 데이터 센터의 최근 보안 침해를 조사하면서 다양한 로그를 살펴보았습니다. 아래의 각 로그는 회사의 보안정보 및 이벤트 관리 서버를 통해 보고된 각종 보안장비에서 수집된 것입니다.
로그:
로그 1:
2월 5일 23:55:37.743: %SEC-6-IPACCESSLOGS: 목록 10 거부 10.2.5.81 3 패킷 로그 2:
HTTP://www.company.com/index.php?user=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa 로그 3:
보안 오류 경고
이벤트 ID 50: RDP 프로토콜 구성 요소 X.224가 프로토콜 스트림에서 오류를 감지하고 클라이언트 로그 4의 연결을 끊었습니다.
인코더 oe = 새로운 OracleEncoder();
문자열 쿼리 = "user_data WHERE user_name = '에서 user_id 선택
+ oe.encode ( req.getParameter("userID") ) + " ' 및 user_password = ' "
+ oe.encode ( req.getParameter("pwd") ) +" ' ";
취약점
버퍼 오버 플로우
SQL 주입
ACL
XSS
다음 중 보안 침해와 가장 관련이 있을 수 있는 로그 및 취약점은 무엇입니까? (2개 선택).
로그:
로그 1:
2월 5일 23:55:37.743: %SEC-6-IPACCESSLOGS: 목록 10 거부 10.2.5.81 3 패킷 로그 2:
HTTP://www.company.com/index.php?user=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa 로그 3:
보안 오류 경고
이벤트 ID 50: RDP 프로토콜 구성 요소 X.224가 프로토콜 스트림에서 오류를 감지하고 클라이언트 로그 4의 연결을 끊었습니다.
인코더 oe = 새로운 OracleEncoder();
문자열 쿼리 = "user_data WHERE user_name = '에서 user_id 선택
+ oe.encode ( req.getParameter("userID") ) + " ' 및 user_password = ' "
+ oe.encode ( req.getParameter("pwd") ) +" ' ";
취약점
버퍼 오버 플로우
SQL 주입
ACL
XSS
다음 중 보안 침해와 가장 관련이 있을 수 있는 로그 및 취약점은 무엇입니까? (2개 선택).
CAS-003 문제 274
네트워크 엔지니어가 네트워크 경계를 업그레이드하고 새 방화벽, IDS 및 외부 에지 라우터를 설치하고 있습니다. IDS는 증가된 UDP 트래픽을 보고하고 내부 라우터는 높은 사용률을 보고합니다. 다음 중 최상의 솔루션은 무엇입니까?
CAS-003 문제 275
A large hospital has implemented BYOD to allow doctors and specialists the ability to access patient medical records on their tablets. The doctors and specialists access patient records over the hospital's guest WiFi network which is isolated from the internal network with appropriate security controls. The patient records management system can be accessed from the guest network and require two factor authentication. Using a remote desktop type interface, the doctors and specialists can interact with the hospital's system. Cut and paste and printing functions are disabled to prevent the copying of data to BYOD devices. Which of the following are of MOST concern? (Select TWO).
