CAS-002 Exam Details

  • Exam Code
    :CAS-002
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :733 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-002 Online Questions & Answers

  • Question 641:

    A security engineer at a bank has detected a Zeus variant, which relies on covert communication channels to receive new instructions and updates from the malware developers. As a result, NIPS and AV systems did not detect the configuration files received by staff in emails that appeared as normal files. Which of the following BEST describes the technique used by the malware developers?

    A. Perfect forward secrecy
    B. Stenography
    C. Diffusion
    D. Confusion
    E. Transport encryption

  • Question 642:

    The security team for Company XYZ has determined that someone from outside the organization has obtained sensitive information about the internal organization by querying the external DNS server of the company. The security manager is tasked with making sure this problem does not occur in the future. How would the security manager address this problem?

    A. Implement a split DNS, only allowing the external DNS server to contain information about domains that only the outside world should be aware, and an internal DNS server to maintain authoritative records for internal systems.
    B. Implement a split DNS, only allowing the external DNS server to contain information about internal domain resources that the outside world would be interested in, and an internal DNS server to maintain authoritative records for internal systems.
    C. Implement a split DNS, only allowing the external DNS server to contain information about domains that only the outside world should be aware, and an internal DNS server to maintain non-authoritative records for external systems.
    D. Implement a split DNS, only allowing the internal DNS server to contain information about domains the outside world should be aware of, and an external DNS server to maintain authoritative records for internal systems.

  • Question 643:

    The helpdesk is receiving multiple calls about slow and intermittent Internet access from the finance department. The following information is compiled:

    Caller 1, IP 172.16.35.217, NETMASK 255.255.254.0

    Caller 2, IP 172.16.35.53, NETMASK 255.255.254.0

    Caller 3, IP 172.16.35.173, NETMASK 255.255.254.0

    All callers are connected to the same switch and are routed by a router with five built-in interfaces. The upstream router interface's MAC is 00-01-42-32-ab-1a

    A packet capture shows the following:

    09:05:15.934840 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)

    09:06:16.124850 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)

    09:07:25.439811 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)

    09:08:10.937590 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2305, seq 1, length 65534

    09:08:10.937591 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2306, seq 2, length 65534

    09:08:10.937592 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2307, seq 3, length 65534

    Which of the following is occurring on the network?

    A. A man-in-the-middle attack is underway on the network.
    B. An ARP flood attack is targeting at the router.
    C. The default gateway is being spoofed on the network.
    D. A denial of service attack is targeting at the router.

  • Question 644:

    To support a software security initiative business case, a project manager needs to provide a cost benefit analysis. The project manager has asked the security consultant to perform a return on investment study. It has been estimated that by spending $300,000 on the software security initiative, a 30% savings in cost will be realized for each project. Based on an average of 8 software projects at a current cost of $50,000 each, how many years will it take to see a positive ROI?

    A. Nearly four years
    B. Nearly six years
    C. Within the first year
    D. Nearly three years

  • Question 645:

    An organization must comply with a new regulation that requires the organization to determine if an external attacker is able to gain access to its systems from outside the network. Which of the following should the company conduct to meet the regulation's criteria?

    A. Conduct a compliance review
    B. Conduct a vulnerability assessment
    C. Conduct a black box penetration test
    D. Conduct a full system audit

  • Question 646:

    In developing a new computing lifecycle process for a large corporation, the security team is developing the process for decommissioning computing equipment. In order to reduce the potential for data leakage, which of the following should the team consider? (Select TWO).

    A. Erase all files on drive
    B. Install of standard image
    C. Remove and hold all drives
    D. Physical destruction
    E. Drive wipe

  • Question 647:

    A security consultant is evaluating forms which will be used on a company website. Which of the following techniques or terms is MOST effective at preventing malicious individuals from successfully exploiting programming flaws in the website?

    A. Anti-spam software
    B. Application sandboxing
    C. Data loss prevention
    D. Input validation

  • Question 648:

    Which of the following describes a risk and mitigation associated with cloud data storage?

    A. Risk: Shared hardware caused data leakage Mitigation: Strong encryption at rest
    B. Risk: Offsite replication Mitigation: Multi-site backups
    C. Risk: Data loss from de-duplication Mitigation: Dynamic host bus addressing
    D. Risk: Combined data archiving Mitigation: Two-factor administrator authentication

  • Question 649:

    The security administrator has just installed an active\passive cluster of two firewalls for enterprise perimeter defense of the corporate network. Stateful firewall inspection is being used in the firewall implementation. There have been numerous reports of dropped connections with external clients.

    Which of the following is MOST likely the cause of this problem?

    A. TCP sessions are traversing one firewall and return traffic is being sent through the secondary firewall and sessions are being dropped.
    B. TCP and UDP sessions are being balanced across both firewalls and connections are being dropped because the session IDs are not recognized by the secondary firewall.
    C. Prioritize UDP traffic and associated stateful UDP session information is traversing the passive firewall causing the connections to be dropped.
    D. The firewall administrator connected a dedicated communication cable between the firewalls in order to share a single state table across the cluster causing the sessions to be dropped.

  • Question 650:

    A retail bank has had a number of issues in regards to the integrity of sensitive information across all of its customer databases. This has resulted in the bank's share price decreasing in value by 50% and regulatory intervention and

    monitoring.

    The new Chief Information Security Officer (CISO) as a result has initiated a program of work to solve the issues.

    The business has specified that the solution needs to be enterprise grade and meet the following requirements:

    Be across all major platforms, applications and infrastructure. Be able to track user and administrator activity. Does not significantly degrade the performance of production platforms, applications, and infrastructures.

    Real time incident reporting.

    Manageable and has meaningful information.

    Business units are able to generate reports in a timely manner of the unit's system assets.

    In order to solve this problem, which of the following security solutions will BEST meet the above requirements? (Select THREE).

    A. Implement a security operations center to provide real time monitoring and incident response with self service reporting capability.
    B. Implement an aggregation based SIEM solution to be deployed on the log servers of the major platforms, applications, and infrastructure.
    C. Implement a security operations center to provide real time monitoring and incident response and an event correlation dashboard with self service reporting capability.
    D. Ensure that the network operations center has the tools to provide real time monitoring and incident response and an event correlation dashboard with self service reporting capabilities.
    E. Implement an agent only based SIEM solution to be deployed on all major platforms, applications, and infrastructures.
    F. Ensure appropriate auditing is enabled to capture the required information.
    G. Manually pull the logs from the major platforms, applications, and infrastructures to a central secure server.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.