CAS-002 Exam Details

  • Exam Code
    :CAS-002
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :733 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-002 Online Questions & Answers

  • Question 291:

    The Chief Executive Officer (CEO) of a company that allows telecommuting has challenged the Chief Security Officer's (CSO) request to harden the corporate network's perimeter. The CEO argues that the company cannot protect its employees at home, so the risk at work is no different. Which of the following BEST explains why this company should proceed with protecting its corporate network boundary?

    A. The corporate network is the only network that is audited by regulators and customers.
    B. The aggregation of employees on a corporate network makes it a more valuable target for attackers.
    C. Home networks are unknown to attackers and less likely to be targeted directly.
    D. Employees are more likely to be using personal computers for general web browsing when they are at home.

  • Question 292:

    A large international business has completed the acquisition of a small business and it is now in the process of integrating the small business' IT department. Both parties have agreed that the large business will retain 95% of the smaller business' IT staff. Additionally, the larger business has a strong interest in specific processes that the smaller business has in place to handle its regional interests. Which of the following IT security related objectives should the small business' IT staff consider reviewing during the integration process? (Select TWO).

    A. How the large business operational procedures are implemented.
    B. The memorandum of understanding between the two businesses.
    C. New regulatory compliance requirements.
    D. Service level agreements between the small and the large business.
    E. The initial request for proposal drafted during the merger.
    F. The business continuity plan in place at the small business.

  • Question 293:

    A business owner has raised concerns with the Chief Information Security Officer (CISO) because money has been spent on IT security infrastructure, but corporate assets are still found to be vulnerable. The business recently implemented a patch management product and SOE hardening initiative. A third party auditor reported findings against the business because some systems were missing patches. Which of the following statements BEST describes this situation?

    A. The business owner is at fault because they are responsible for patching the systems and have already been given patch management and SOE hardening products.
    B. The audit findings are invalid because remedial steps have already been applied to patch servers and the remediation takes time to complete.
    C. The CISO has not selected the correct controls and the audit findings should be assigned to them instead of the business owner.
    D. Security controls are generally never 100% effective and gaps should be explained to stakeholders and managed accordingly.

  • Question 294:

    A security auditor suspects two employees of having devised a scheme to steal money from the company. While one employee submits purchase orders for personal items, the other employee approves these purchase orders. The auditor has contacted the human resources director with suggestions on how to detect such illegal activities. Which of the following should the human resource director implement to identify the employees involved in these activities and reduce the risk of this activity occurring in the future?

    A. Background checks
    B. Job rotation
    C. Least privilege
    D. Employee termination procedures

  • Question 295:

    In order to reduce costs and improve employee satisfaction, a large corporation is creating a BYOD policy. It will allow access to email and remote connections to the corporate enterprise from personal devices; provided they are on an approved device list. Which of the following security measures would be MOST effective in securing the enterprise under the new policy? (Select TWO).

    A. Provide free email software for personal devices.
    B. Encrypt data in transit for remote access.
    C. Require smart card authentication for all devices.
    D. Implement NAC to limit insecure devices access.
    E. Enable time of day restrictions for personal devices.

  • Question 296:

    A security manager for a service provider has approved two vendors for connections to the service provider backbone. One vendor will be providing authentication services for its payment card service, and the other vendor will be providing maintenance to the service provider infrastructure sites. Which of the following business agreements is MOST relevant to the vendors and service provider's relationship?

    A. Memorandum of Agreement
    B. Interconnection Security Agreement
    C. Non-Disclosure Agreement
    D. Operating Level Agreement

  • Question 297:

    The Chief Executive Officer (CEO) of a large prestigious enterprise has decided to reduce business costs by outsourcing to a third party company in another country. Functions to be outsourced include: business analysts, testing, software development and back office functions that deal with the processing of customer data. The Chief Risk Officer (CRO) is concerned about the outsourcing plans. Which of the following risks are MOST likely to occur if adequate controls are not implemented?

    A. Geographical regulation issues, loss of intellectual property and interoperability agreement issues
    B. Improper handling of client data, interoperability agreement issues and regulatory issues
    C. Cultural differences, increased cost of doing business and divestiture issues
    D. Improper handling of customer data, loss of intellectual property and reputation damage

  • Question 298:

    A security architect is assigned to a major software development project. The software development team has a history of writing bug prone, inefficient code, with multiple security flaws in every release. The security architect proposes implementing secure coding standards to the project manager. The secure coding standards will contain detailed standards for:

    A. error handling, input validation, memory use and reuse, race condition handling, commenting, and preventing typical security problems.
    B. error prevention, requirements validation, memory use and reuse, commenting typical security problems, and testing code standards.
    C. error elimination, trash collection, documenting race conditions, peer review, and typical security problems.
    D. error handling, input validation, commenting, preventing typical security problems, managing customers, and documenting extra requirements.

  • Question 299:

    A company receives an e-discovery request for the Chief Information Officer's (CIO's) email data. The storage administrator reports that the data retention policy relevant to their industry only requires one year of email data. However the storage administrator also reports that there are three years of email data on the server and five years of email data on backup tapes. How many years of data MUST the company legally provide?

    A. 1
    B. 2
    C. 3
    D. 5

  • Question 300:

    A company has migrated its data and application hosting to a cloud service provider (CSP). To meet its future needs, the company considers an IdP. Why might the company want to select an IdP that is separate from its CSP? (Select TWO).

    A. A circle of trust can be formed with all domains authorized to delegate trust to an IdP
    B. Identity verification can occur outside the circle of trust if specified or delegated
    C. Replication of data occurs between the CSP and IdP before a verification occurs
    D. Greater security can be provided if the circle of trust is formed within multiple CSP domains
    E. Faster connections can occur between the CSP and IdP without the use of SAML

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.