CAS-002 Exam Details

  • Exam Code
    :CAS-002
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :733 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-002 Online Questions & Answers

  • Question 631:

    Which of the following implementations of a continuous monitoring risk mitigation strategy is correct?

    A. Audit successful and failed events, transfer logs to a centralized server, institute computer assisted audit reduction, and email alerts to NOC staff hourly.
    B. Audit successful and critical failed events, transfer logs to a centralized server once a month, tailor logged event thresholds to meet organization goals, and display alerts in real time when thresholds are approached.
    C. Audit successful and failed events, transfer logs to a centralized server, institute computer assisted audit reduction, tailor logged event thresholds to meet organization goals, and display alerts in real time when thresholds are exceeded.
    D. Audit failed events only, transfer logs to a centralized server, implement manual audit reduction, tailor logged event thresholds to meet organization goals, and display alerts in real time when thresholds are approached and exceeded.

  • Question 632:

    Company ABC has entered into a marketing agreement with Company XYZ, whereby ABC will share some of its customer information with XYZ. However, XYZ can only contact ABC customers who explicitly agreed to being contacted by third parties. Which of the following documents would contain the details of this marketing agreement?

    A. BPA
    B. ISA
    C. NDA
    D. SLA

  • Question 633:

    Using SSL, an administrator wishes to secure public facing server farms in three subdomains:

    dc1.east.company.com, dc2.central.company.com, and dc3.west.company.com. Which of the following is the number of wildcard SSL certificates that should be purchased?

    A. 1
    B. 2
    C. 3
    D. 6

  • Question 634:

    An organization would like to allow employees to use their network username and password to access a third-party service. The company is using Active Directory Federated Services for their directory service. Which of the following should the company ensure is supported by the third-party? (Select TWO).

    A. LDAP/S
    B. SAML
    C. NTLM
    D. OAUTH
    E. Kerberos

  • Question 635:

    A software development manager is taking over an existing software development project. The team currently suffers from poor communication due to a long delay between requirements documentation and feature delivery. This gap is resulting in an above average number of security-related bugs making it into production. Which of the following development methodologies is the team MOST likely using now?

    A. Agile
    B. Waterfall
    C. Scrum
    D. Spiral

  • Question 636:

    An ISP is peering with a new provider and wishes to disclose which autonomous system numbers should be allowed through BGP for network transport. Which of the following should contain this information?

    A. Memorandum of Understanding
    B. Interconnection Security Agreement
    C. Operating Level Agreement
    D. Service Level Agreement

  • Question 637:

    An application present on the majority of an organization's 1,000 systems is vulnerable to a buffer overflow attack. Which of the following is the MOST comprehensive way to resolve the issue?

    A. Deploy custom HIPS signatures to detect and block the attacks.
    B. Validate and deploy the appropriate patch.
    C. Run the application in terminal services to reduce the threat landscape.
    D. Deploy custom NIPS signatures to detect and block the attacks.

  • Question 638:

    A user reports that the workstation's mouse pointer is moving and files are opening automatically. Which of the following should the user perform?

    A. Unplug the network cable to avoid network activity.
    B. Reboot the workstation to see if problem occurs again.
    C. Turn off the computer to avoid any more issues.
    D. Contact the incident response team for direction.

  • Question 639:

    A bank now has a major initiative to virtualize as many servers as possible, due to power and rack space capacity at both data centers. The bank has prioritized by virtualizing older servers first as the hardware is nearing end-of-life.

    The two initial migrations include:

    Windows 2000 hosts: domain controllers and front-facing web servers RHEL3 hosts: front-facing web servers

    Which of the following should the security consultant recommend based on best practices?

    A. One data center should host virtualized web servers and the second data center should host the virtualized domain controllers.
    B. One virtual environment should be present at each data center, each housing a combination of the converted Windows 2000 and RHEL3 virtual machines.
    C. Each data center should contain one virtual environment for the web servers and another virtual environment for the domain controllers.
    D. Each data center should contain one virtual environment housing converted Windows 2000 virtual machines and converted RHEL3 virtual machines.

  • Question 640:

    An organization has several production critical SCADA supervisory systems that cannot follow the normal 30-day patching policy. Which of the following BEST maximizes the protection of these systems from malicious software?

    A. Configure a firewall with deep packet inspection that restricts traffic to the systems
    B. Configure a separate zone for the systems and restrict access to known ports
    C. Configure the systems to ensure only necessary applications are able to run
    D. Configure the host firewall to ensure only the necessary applications have listening ports

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.