CAS-003 문제 376

Ann, a CIRT member, is conducting incident response activities on a network that consists of several hundred virtual servers and thousands of endpoints and users. The network generates more than 10,000 log messages per second. The enterprise belong to a large, web-based cryptocurrency startup, Ann has distilled the relevant information into an easily digestible report for executive management . However, she still needs to collect evidence of the intrusion that caused the incident. Which of the following should Ann use to gather the required information?

CAS-003 문제 377

A security engineer has been hired to design a device that will enable the exfiltration of data from within a
well-defended network perimeter during an authorized test. The device must bypass all firewalls and NIDS
in place, as well as allow for the upload of commands from a centralized command and control answer.
The total cost of the device must be kept to a minimum in case the device is discovered during an
assessment. Which of the following tools should the engineer load onto the device being designed?

CAS-003 문제 378

An information security manager is concerned that connectivity used to configure and troubleshoot critical network devices could be attacked. The manager has tasked a network security engineer with meeting the following requirements:
Encrypt all traffic between the network engineer and critical devices.

Segregate the different networking planes as much as possible.

Do not let access ports impact configuration tasks.

Which of the following would be the BEST recommendation for the network security engineer to present?

CAS-003 문제 379

매일 아침 9시에 VDI 구현의 모든 가상 데스크톱이 매우 느려지고 응답하지 않습니다. 가동 중단은 약 10분 동안 지속되며, 그 후 모든 것이 올바르게 다시 실행됩니다. 관리자는 매일 아침 9시에 부팅되는 씬 클라이언트 랩에서 문제를 추적했습니다. 다음 중 문제의 가장 가능성이 높은 원인과 최선의 해결책은 무엇입니까? (2개 선택).

CAS-003 문제 380

A Chief Information Securiy Officer (CISO) is reviewing technical documentation from various regional offices and notices some key differences between these groups. The CISO has not discovered any governance documentation. The CISO creates the following chart to visualize the differences among the networking used.

Which of the following would be the CISO's MOST immediate concern?