Exam Details

  • Exam Code
    :CAS-002
  • Exam Name
    :CompTIA Advanced Security Practitioner Exam
  • Certification
    :CompTIA Advanced Security Practitioner
  • Vendor
    :CompTIA
  • Total Questions
    :733 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CompTIA Advanced Security Practitioner CAS-002 Questions & Answers

  • Question 11:

    Which of the following is the MOST cost-effective solution for sanitizing a DVD with sensitive information on it?

    A. Write over the data

    B. Purge the data

    C. Incinerate the DVD

    D. Shred the DVD

  • Question 12:

    A company has decided to use the SDLC for the creation and production of a new information system. The security administrator is training all users on how to protect company information while using the new system, along with being able to recognize social engineering attacks. Senior Management must also formally approve of the system prior to it going live. In which of the following phases would these security controls take place?

    A. Operations and Maintenance

    B. Implementation

    C. Acquisition and Development

    D. Initiation

  • Question 13:

    Wireless users are reporting issues with the company's video conferencing and VoIP systems. The security administrator notices DOS attacks on the network that are affecting the company's VoIP system (i.e. premature call drops and garbled call signals). The security administrator also notices that the SIP servers are unavailable during these attacks. Which of the following security controls will MOST likely mitigate the VoIP DOS attacks on the network? (Select TWO).

    A. Configure 802.11b on the network

    B. Configure 802.1q on the network

    C. Configure 802.11e on the network

    D. Update the firewall managing the SIP servers

    E. Update the HIDS managing the SIP servers

  • Question 14:

    The security administrator of a small private firm is researching and putting together a proposal to purchase an IPS to replace an existing IDS. A specific brand and model has been selected, but the security administrator needs to gather various cost information for that product. Which of the following documents would perform a cost analysis report and include information such as payment terms?

    A. RFI

    B. RTO

    C. RFQ

    D. RFC

  • Question 15:

    A security administrator of a large private firm is researching and putting together a proposal to purchase an IPS. The specific IPS type has not been selected, and the security administrator needs to gather information from several vendors to determine a specific product. Which of the following documents would assist in choosing a specific brand and model?

    A. RFC

    B. RTO

    C. RFQ

    D. RFI

  • Question 16:

    A company has purchased a new system, but security personnel are spending a great deal of time on system maintenance. A new third party vendor has been selected to maintain and manage the company's system. Which of the following document types would need to be created before any work is performed?

    A. IOS

    B. ISA

    C. SLA

    D. OLA

  • Question 17:

    Which of the following must be taken into consideration for e-discovery purposes when a legal case is first presented to a company?

    A. Data ownership on all files

    B. Data size on physical disks

    C. Data retention policies on only file servers

    D. Data recovery and storage

  • Question 18:

    A business is currently in the process of upgrading its network infrastructure to accommodate a personnel growth of over fifty percent within the next six months. All preliminary planning has been completed and a risk assessment plan is being adopted to decide which security controls to put in place throughout each phase.

    Which of the following risk responses is MOST likely being considered if the business is creating an SLA with a third party?

    A. Accepting risk

    B. Mitigating risk

    C. Identifying risk

    D. Transferring risk

  • Question 19:

    Several critical servers are unresponsive after an update was installed. Other computers that have not yet received the same update are operational, but are vulnerable to certain buffer overflow attacks. The security administrator is required to ensure all systems have the latest updates while minimizing any downtime.

    Which of the following is the BEST risk mitigation strategy to use to ensure a system is properly updated and operational?

    A. Distributed patch management system where all systems in production are patched as updates are released.

    B. Central patch management system where all systems in production are patched by automatic updates as they are released.

    C. Central patch management system where all updates are tested in a lab environment after being installed on a live production system.

    D. Distributed patch management system where all updates are tested in a lab environment prior to being installed on a live production system.

  • Question 20:

    Which of the following displays an example of a XSS attack?

    A.

    B. Checksums-Sha1:7be9e9bac3882beab1abb002bb5cd2302c76c48d 1157 xfig_3.2.5.b-1.dsc e0e3c9a9df6fac8f1536c2209025577edb1d1d9e 5770796 xfig_3.2.5.b.orig.tar.gz d474180fbeb6955e79bfc67520ad775a87b68d80 46856 xfig_3.2.5.b-1.diff.gz ddcba53dffd08e5d37492fbf99fe93392943c7b0 3363512 xfig-doc_3.2.5.b-1_all.deb 7773821c1a925978306d6c75ff5c579b018a2ac6 1677778 xfig-libs_3.2.5.b-1_all.deb b26c18cfb2ee2dc071b0e3bed6205c1fc0655022 739228 xfig_3.2.5.b-1_amd64.deb

    C.

    Username: PassworD.

    D. #include char *code = "AAAABBBBCCCCDDD"; //including the character '\0' size = 16 bytes void main() {char buf[8]; strcpy(buf, code); }

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.