CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 241:

    While traveling to another state, the Chief Financial Officer (CFO) forgot to submit payroll for the company The CFO quickly gained access to the corporate network through the high-speed wireless network provided by the hotel and

    completed the task. Upon returning from the business trip, the CFO was told no one received their weekly pay due to a malware attack on the system.

    Which of the following is the MOST likely cause of the secunty breach?

    A. The security manager did not enforce automatic VPN connection.
    B. The company's server did not have endpoint security enabled.
    C. The hotel did not require a wireless password to authenticate.
    D. The laptop did not have the host-based firewall properly configured.

  • Question 242:

    The Chief Information Security Officer (CISO) of a new company is looking for a comprehensive assessment of the company's application services Which of the following would provide the MOST accurate number of weaknesses?

    A. White-box penetration test
    B. Internal vulnerability scanning
    C. Internal controls audit
    D. Third-party red-team engagement

  • Question 243:

    A security analyst has received the following requirements for the implementation of enterprise credential management software.

    1.

    The software must have traceability back to an individual

    2.

    Credentials must remain unknown to the vendor at all times

    3.

    There must be forced credential changes upon ID checkout

    4.

    Complexity requirements must be enforced.

    5.

    The software must be quickly and easily scalable with max mum availability

    Which of the following vendor configurations would BEST meet these requirements?

    A. Credentials encrypted in transit and then stored, hashed and salted in a vendor's cloud, where the vendor handles key management
    B. Credentials stored, hashed, and salted on each local machine
    C. Credentials encrypted in transit and stored in a vendor's cloud, where the enterprise retains the keys
    D. Credentials encrypted in transit and stored on an internal network server with backups that are taken on a weekly basis

  • Question 244:

    SIMULATION

  • Question 245:

    A company has deployed MFA Some employees, however, report they ate not gelling a notification on their mobile device Other employees report they downloaded a common authenticates application but when they tap the code in the application it just copies the code to memory instead of confirming the authentication attempt Which of the following are the MOST likely explanations for these scenarios? (Select TWO)

    A. The company is using a claims-based authentication system for MFA
    B. These are symptoms of known compatibility issues with OAuth 1 0
    C. OpenID Connect requires at least one factor to be a biometric
    D. The company does not allow an SMS authentication method
    E. The WAYF method requires a third factor before the authentication process can complete
    F. A vendor-specific authenticator application is needed for push notifications

  • Question 246:

    An application developer has been informed of a web application that is susceptible to a clickjacking vulnerability Which of the following code snippets would be MOST applicable to resolve this vulnerability?

    A. Content-Security-Policy frame-ancestors: 'none'
    B. $escaped_command = escapeshellcmd(Sargs); exec ($escaped_command, Soutput, $return_var);
    C. sqlQuery= 'SELECT * FROM custTable WHERE User=? AND Pass=?' parameters.add("User", username)
    D. require 'digest/sha2' sha256 = Digest::SHA2.new(256)

  • Question 247:

    A security analyst has been assigned incident response duties and must instigate the response on a Windows device that appears to be compromised. Which of the following commands should be executed on the client FIRST?

    A. Option A
    B. Option B
    C. Option C
    D. Option D

  • Question 248:

    IT staff within a company often conduct remote desktop sharing sessions with vendors to troubleshoot vendor product-related issues. Drag and drop the following security controls to match the associated security concern. Options may be used once or not at all.

    Select and Place:

  • Question 249:

    Ann, a security administrator, is conducting an assessment on a new firewall, which was placed at the perimeter of a network containing PII. Ann runs the following commands on a server (10.0.1.19) behind the firewall:

    From her own workstation (192.168.2.45) outside the firewall, Ann then runs a port scan against the server and records the following packet capture of the port scan:

    Connectivity to the server from outside the firewall worked as expected prior to executing these commands.

    Which of the following can be said about the new firewall?

    A. It is correctly dropping all packets destined for the server.
    B. It is not blocking or filtering any traffic to the server.
    C. Iptables needs to be restarted.
    D. The IDS functionality of the firewall is currently disabled.

  • Question 250:

    An insurance company has an online quoting system for insurance premiums. It allows potential customers to fill in certain details about their car and obtain a quote. During an investigation, the following patterns were detected:

    Pattern 1 -Analysis of the logs identifies that insurance premium forms are being filled in but only single fields are incrementally being updated.

    Pattern 2 -For every quote completed, a new customer number is created; due to legacy systems, customer numbers are running out.

    Which of the following is the attack type the system is susceptible to, and what is the BEST way to defend against it? (Select TWO).

    A. Apply a hidden field that triggers a SIEM alert
    B. Cross site scripting attack
    C. Resource exhaustion attack
    D. Input a blacklist of all known BOT malware IPs into the firewall
    E. SQL injection
    F. Implement an inline WAF and integrate into SIEM
    G. Distributed denial of service
    H. Implement firewall rules to block the attacking IP addresses

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.