Exam Details

  • Exam Code
    :CAS-002
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :733 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CompTIA Certifications CAS-002 Questions & Answers

  • Question 311:

    During a software development project review, the cryptographic engineer advises the project manager that security can be greatly improved by significantly slowing down the runtime of a hashing algorithm and increasing the entropy by passing the input and salt back during each iteration. Which of the following BEST describes what the engineer is trying to achieve?

    A. Monoalphabetic cipher

    B. Confusion

    C. Root of trust

    D. Key stretching

    E. Diffusion

  • Question 312:

    Every year, the accounts payable employee, Ann, takes a week off work for a vacation. She typically completes her responsibilities remotely during this week. Which of the following policies, when implemented, would allow the company to audit this employee's work and potentially discover improprieties?

    A. Job rotation

    B. Mandatory vacations

    C. Least privilege

    D. Separation of duties

  • Question 313:

    When generating a new key pair, a security application asks the user to move the mouse and type random characters on the keyboard. Which of the following BEST describes why this is necessary?

    A. The user needs a non-repudiation data source in order for the application to generate the key pair.

    B. The user is providing entropy so the application can use random data to create the key pair.

    C. The user is providing a diffusion point to the application to aid in creating the key pair.

    D. The application is requesting perfect forward secrecy from the user in order to create the key pair.

  • Question 314:

    Company XYZ has purchased and is now deploying a new HTML5 application. The company wants to hire a penetration tester to evaluate the security of the client and server components of the proprietary web application before launch. Which of the following is the penetration tester MOST likely to use while performing black box testing of the security of the company's purchased application? (Select TWO).

    A. Code review

    B. Sandbox

    C. Local proxy

    D. Fuzzer

    E. Web vulnerability scanner

  • Question 315:

    Company XYZ has employed a consultant to perform a controls assessment of the HR system, backend business operations, and the SCADA system used in the factory. Which of the following correctly states the risk management options that the consultant should use during the assessment?

    A. Risk reduction, risk sharing, risk retention, and risk acceptance.

    B. Avoid, transfer, mitigate, and accept.

    C. Risk likelihood, asset value, and threat level.

    D. Calculate risk by determining technical likelihood and potential business impact.

  • Question 316:

    The Universal Research Association has just been acquired by the Association of Medical Business Researchers. The new conglomerate has funds to upgrade or replace hardware as part of the acquisition, but cannot fund labor for major software projects. Which of the following will MOST likely result in some IT resources not being integrated?

    A. One of the companies may use an outdated VDI.

    B. Corporate websites may be optimized for different web browsers.

    C. Industry security standards and regulations may be in conflict.

    D. Data loss prevention standards in one company may be less stringent.

  • Question 317:

    A security code reviewer has been engaged to manually review a legacy application. A number of systemic issues have been uncovered relating to buffer overflows and format string vulnerabilities.

    The reviewer has advised that future software projects utilize managed code platforms if at all possible.

    Which of the following languages would suit this recommendation? (Select TWO).

    A. C

    B. C#

    C. C++

    D. Perl

    E. Java

  • Question 318:

    Company XYZ is in negotiations to acquire Company ABC for $1.2millon. Due diligence activities have uncovered systemic security issues in the flagship product of Company ABC. It has been established that a complete product rewrite would be needed with average estimates indicating a cost of $1.6millon. Which of the following approaches should the risk manager of Company XYZ recommend?

    A. Transfer the risk

    B. Accept the risk

    C. Mitigate the risk

    D. Avoid the risk

  • Question 319:

    select id, firstname, lastname from authors

    User input= firstname= Hack;man

    lastname=Johnson

    Which of the following types of attacks is the user attempting?

    A. XML injection

    B. Command injection

    C. Cross-site scripting

    D. SQL injection

  • Question 320:

    An organization has just released a new mobile application for its customers. The application has an inbuilt browser and native application to render content from existing websites and the organization's new web services gateway. All rendering of the content is performed on the mobile application.

    The application requires SSO between the application, the web services gateway and legacy UI. Which of the following controls MUST be implemented to securely enable SSO?

    A. A registration process is implemented to have a random number stored on the client.

    B. The identity is passed between the applications as a HTTP header over REST.

    C. Local storage of the authenticated token on the mobile application is secured.

    D. Attestation of the XACML payload to ensure that the client is authorized.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.