CAS-002 Exam Details

  • Exam Code
    :CAS-002
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :733 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-002 Online Questions & Answers

  • Question 111:

    An external auditor has found that IT security policies in the organization are not maintained and in some cases are nonexistent. As a result of the audit findings, the CISO has been tasked with the objective of establishing a mechanism to manage the lifecycle of IT security policies. Which of the following can be used to BEST achieve the CISO's objectives?

    A. CoBIT
    B. UCF
    C. ISO 27002
    D. eGRC

  • Question 112:

    In an effort to minimize costs, the management of a small candy company wishes to explore a cloud service option for the development of its online applications. The company does not wish to invest heavily in IT infrastructure. Which of the following solutions should be recommended?

    A. A public IaaS
    B. A public PaaS
    C. A public SaaS
    D. A private SaaS
    E. A private IaaS
    F. A private PaaS

  • Question 113:

    The company's marketing department needs to provide more real-time interaction with its partners and consumers and decides to move forward with a presence on multiple social networking sites for sharing information. Which of the following minimizes the potential exposure of proprietary information?

    A. Require each person joining the company's social networking initiative to accept a non- disclosure agreement.
    B. Establish a specific set of trained people that can release information on the organization's behalf.
    C. Require a confidential statement be attached to all information released to the social networking sites.
    D. Establish a social media usage policy and provide training to all marketing employees.

  • Question 114:

    Within the company, there is executive management pressure to start advertising to a new target market. Due to the perceived schedule and budget inefficiencies of engaging a technology business unit to commission a new micro-site, the marketing department is engaging third parties to develop the site in order to meet time-to-market demands. From a security perspective, which of the following options BEST balances the needs between marketing and risk management?

    A. The third party should be contractually obliged to perform adequate security activities, and evidence of those activities should be confirmed by the company prior to launch.
    B. Outsourcing is a valid option to increase time-to-market. If a security incident occurs, it is not of great concern as the reputational damage will be the third party's responsibility.
    C. The company should never outsource any part of the business that could cause a security or privacy incident. It could lead to legal and compliance issues.
    D. If the third party has an acceptable record to date on security compliance and is provably faster and cheaper, then it makes sense to outsource in this specific situation.

  • Question 115:

    During user acceptance testing, the security administrator believes to have discovered an issue in the login prompt of the company's financial system. While entering the username and password, the program crashed and displayed the system command prompt. The security administrator believes that one of the fields may have been mistyped and wants to reproduce the issue to report it to the software developers. Which of the following should the administrator use to reproduce the issue?

    A. The administrator should enter a username and use an offline password cracker in brute force mode.
    B. The administrator should use a network analyzer to determine which packet caused the system to crash.
    C. The administrator should extract the password file and run an online password cracker in brute force mode against the password file.
    D. The administrator should run an online fuzzer against the login screen.

  • Question 116:

    Which of the following protocols only facilitates access control?

    A. XACML
    B. Kerberos
    C. SPML
    D. SAML

  • Question 117:

    A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a strong personal and professional relationship with the senior level staff, have a good handle on compliance and regulatory standards. Therefore, the executive level managers are allowing vendors to play a large role in writing the policy. Having experienced this type of environment in previous positions, and being aware that vendors may not always put the company's interests first, the IT Director decides that while vendor support is important, it is critical that the company writes the policy objectively. Which of the following is the recommendation the IT Director should present to senior staff?

    A. 1) Consult legal, moral, and ethical standards; 2) Draft General Organizational Policy; 3) Specify Functional Implementing Policies; 4) Allow vendors to review and participate in the establishment of focused compliance standards, plans, and procedures
    B. 1) Consult legal and regulatory requirements; 2) Draft General Organizational Policy; 3) Specify Functional Implementing Policies; 4) Establish necessary standards, procedures, baselines, and guidelines
    C. 1) Draft General Organizational Policy; 2) Establish necessary standards and compliance documentation; 3) Consult legal and industry security experts; 4) Determine acceptable tolerance guidelines
    D. 1) Draft a Specific Company Policy Plan; 2) Consult with vendors to review and collaborate with executives; 3) Add industry compliance where needed; 4) Specify Functional Implementing Policies

  • Question 118:

    Due to cost and implementation time pressures, a security architect has allowed a NAS to be used instead of a SAN for a non-critical, low volume database. Which of the following would make a NAS unsuitable for a business critical, high volume database application that required a high degree of data confidentiality and data availability? (Select THREE).

    A. File level transfer of data
    B. Zoning and LUN security
    C. Block level transfer of data
    D. Multipath
    E. Broadcast storms
    F. File level encryption
    G. Latency

  • Question 119:

    Company XYZ provides cable television service to several regional areas. They are currently installing fiber-to-the-home in many areas with hopes of also providing telephone and Internet services. The telephone and Internet services portions of the company will each be separate subsidiaries of the parent company. The board of directors wishes to keep the subsidiaries separate from the parent company. However all three companies must share customer data for the purposes of accounting, billing, and customer authentication. The solution must use open standards, and be simple and seamless for customers, while only sharing minimal data between the companies. Which of the following solutions is BEST suited for this scenario?

    A. The companies should federate, with the parent becoming the SP, and the subsidiaries becoming an IdP.
    B. The companies should federate, with the parent becoming the IdP, and the subsidiaries becoming an SSP.
    C. The companies should federate, with the parent becoming the IdP, and the subsidiaries becoming an SP.
    D. The companies should federate, with the parent becoming the ASP, and the subsidiaries becoming an IdP.

  • Question 120:

    Driven mainly by cost, many companies outsource computing jobs which require a large amount of processor cycles over a short duration to cloud providers. This allows the company to avoid a large investment in computing resources which will only be used for a short time.

    Assuming the provisioned resources are dedicated to a single company, which of the following is the MAIN vulnerability associated with on-demand provisioning?

    A. Traces of proprietary data which can remain on the virtual machine and be exploited
    B. Remnants of network data from prior customers on the physical servers during a compute job
    C. Exposure of proprietary data when in-transit to the cloud provider through IPSec tunnels
    D. Failure of the de-provisioning mechanism resulting in excessive charges for the resources

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.