CAS-002 Exam Details

  • Exam Code
    :CAS-002
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :733 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-002 Online Questions & Answers

  • Question 551:

    After being informed that the company DNS is unresponsive, the system administrator issues the following command from a Linux workstation:

    SSH -p 2020 -l user dnsserver.company.com

    Once at the command prompt, the administrator issues the below commanD.

    Service bind restart

    The system returns the below response:

    Unable to restart BIND

    Which of the following is true about the above situation?

    A. The administrator must use the sudo command in order to restart the service.
    B. The administrator used the wrong SSH port to restart the DNS server.
    C. The service was restarted correctly, but it failed to bind to the network interface.
    D. The service did not restart because the bind command is privileged.

  • Question 552:

    A new IDS device is generating a very large number of irrelevant events. Which of the following would BEST remedy this problem?

    A. Change the IDS to use a heuristic anomaly filter.
    B. Adjust IDS filters to decrease the number of false positives.
    C. Change the IDS filter to data mine the false positives for statistical trending data.
    D. Adjust IDS filters to increase the number of false negatives.

  • Question 553:

    A large organization has recently suffered a massive credit card breach. During the months of Incident Response, there were multiple attempts to assign blame for whose fault it was that the incident occurred. In which part of the incident response phase would this be addressed in a controlled and productive manner?

    A. During the Identification Phase
    B. During the Lessons Learned phase
    C. During the Containment Phase
    D. During the Preparation Phase

  • Question 554:

    A software development manager is taking over an existing software development project. The team currently suffers from poor communication, and this gap is resulting in an above average number of security-related bugs making it into production. Which of the following development methodologies involves daily stand- ups designed to improve communication?

    A. Spiral
    B. Agile
    C. Waterfall
    D. Rapid

  • Question 555:

    A risk manager has decided to use likelihood and consequence to determine the risk of an event occurring to a company asset. Which of the following is a limitation of this approach to risk management?

    A. Subjective and based on an individual's experience.
    B. Requires a high degree of upfront work to gather environment details.
    C. Difficult to differentiate between high, medium, and low risks.
    D. Allows for cost and benefit analysis.
    E. Calculations can be extremely complex to manage.

  • Question 556:

    The security administrator finds unauthorized tables and records, which were not present before, on a Linux database server. The database server communicates only with one web server, which connects to the database server via an

    account with SELECT only privileges.

    Web server logs show the following:

    90.76.165.40 -- [08/Mar/2014:10:54:04] "GET calendar.php?create%20table%20hidden HTTP/1.1" 200 90.76.165.40 -- [08/Mar/2014:10:54:05] "GET ../../../root/.bash_history HTTP/1.1" 200 90.76.165.40 ?- [08/ Mar/2014:10:54:04] "GET index.php? user<;scrip>;Creat<;/scrip>; HTTP/1.1" 200 5724

    The security administrator also inspects the following file system locations on the database server using the command `ls -al /root'

    drwxrwxrwx 11 root root 4096 Sep 28 22:45 .

    drwxr-xr-x 25 root root 4096 Mar 8 09:30 ..

    -rws------ 25 root root 4096 Mar 8 09:30 .bash_history -rw------- 25 root root 4096 Mar 8 09:30 .bash_history -rw------- 25 root root 4096 Mar 8 09:30 .profile -rw------- 25 root root 4096 Mar 8 09:30 .ssh Which of the following attacks was used to compromise the database server and what can the security administrator implement to detect such attacks in the future? (Select TWO).

    A. Privilege escalation
    B. Brute force attack
    C. SQL injection
    D. Cross-site scripting
    E. Using input validation, ensure the following characters are sanitized:
    F. Update crontab with: find / \( -perm -4000 \) ype f rint0 | xargs -0 ls | email.sh
    G. Implement the following PHP directive: $clean_user_input = addslashes($user_input)
    H. Set an account lockout policy

  • Question 557:

    The Chief Executive Officer (CEO) of a large prestigious enterprise has decided to reduce business costs by outsourcing to a third party company in another country. Functions to be outsourced include: business analysts, testing, software development and back office functions that deal with the processing of customer data. The Chief Risk Officer (CRO) is concerned about the outsourcing plans. Which of the following risks are MOST likely to occur if adequate controls are not implemented?

    A. Geographical regulation issues, loss of intellectual property and interoperability agreement issues
    B. Improper handling of client data, interoperability agreement issues and regulatory issues
    C. Cultural differences, increased cost of doing business and divestiture issues
    D. Improper handling of customer data, loss of intellectual property and reputation damage

  • Question 558:

    An online banking application has had its source code updated and is soon to be re-launched. The underlying infrastructure has not been changed. In order to ensure that the application has an appropriate security posture, several security-related activities are required.

    Which of the following security activities should be performed to provide an appropriate level of security testing coverage? (Select TWO).

    A. Penetration test across the application with accounts of varying access levels (i.e. non- authenticated, authenticated, and administrative users).
    B. Code review across critical modules to ensure that security defects, Trojans, and backdoors are not present.
    C. Vulnerability assessment across all of the online banking servers to ascertain host and container configuration lock-down and patch levels.
    D. Fingerprinting across all of the online banking servers to ascertain open ports and services.
    E. Black box code review across the entire code base to ensure that there are no security defects present.

  • Question 559:

    A team of security engineers has applied regulatory and corporate guidance to the design of a corporate network. The engineers have generated an SRTM based on their work and a thorough analysis of the complete set of functional and performance requirements in the network specification. Which of the following BEST describes the purpose of an SRTM in this scenario?

    A. To ensure the security of the network is documented prior to customer delivery
    B. To document the source of all functional requirements applicable to the network
    C. To facilitate the creation of performance testing metrics and test plans
    D. To allow certifiers to verify the network meets applicable security requirements

  • Question 560:

    The helpdesk manager wants to find a solution that will enable the helpdesk staff to better serve company employees who call with computer-related problems. The helpdesk staff is currently unable to perform effective troubleshooting and relies on callers to describe their technology problems. Given that the helpdesk staff is located within the company headquarters and 90% of the callers are telecommuters, which of the following tools should the helpdesk manager use to make the staff more effective at troubleshooting while at the same time reducing company costs? (Select TWO).

    A. Web cameras
    B. Email
    C. Instant messaging
    D. BYOD
    E. Desktop sharing
    F. Presence

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.