CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 261:

    A security technician is incorporating the following requirements in an RFP for a new SIEM:

    New security notifications must be dynamically implemented by the SIEM engine The SIEM must be able to identify traffic baseline anomalies Anonymous attack data from all customers must augment attack detection and risk scoring

    Based on the above requirements, which of the following should the SIEM support? (Choose two.)

    A. Autoscaling search capability
    B. Machine learning
    C. Multisensor deployment
    D. Big Data analytics
    E. Cloud-based management
    F. Centralized log aggregation

  • Question 262:

    Company A is establishing a contractual with Company B. The terms of the agreement are formalized in a document covering the payment terms, limitation of liability, and intellectual property rights. Which of the following documents will MOST likely contain these elements

    A. Company A-B SLA v2.docx
    B. Company A OLA v1b.docx
    C. Company A MSA v3.docx
    D. Company A MOU v1.docx
    E. Company A-B NDA v03.docx

  • Question 263:

    The senior security administrator wants to redesign the company DMZ to minimize the risks associated with both external and internal threats. The DMZ design must support security in depth, change management and configuration processes, and support incident reconstruction. Which of the following designs BEST supports the given requirements?

    A. A dual firewall DMZ with remote logging where each firewall is managed by a separate administrator.
    B. A single firewall DMZ where each firewall interface is managed by a separate administrator and logging to the cloud.
    C. A SaaS based firewall which logs to the company's local storage via SSL, and is managed by the change control team.
    D. A virtualized firewall, where each virtual instance is managed by a separate administrator and logging to the same hardware.

  • Question 264:

    A security architect is designing a new infrastructure using both type 1 and type 2 virtual machines. In addition to the normal complement of security controls (e.g. antivirus, host hardening, HIPS/NIDS) the security architect needs to implement a mechanism to securely store cryptographic keys used to sign code and code modules on the VMs. Which of the following will meet this goal without requiring any hardware pass-through implementations?

    A. vTPM
    B. HSM
    C. TPM
    D. INE

  • Question 265:

    An organization designs and develops safety-critical embedded firmware (inclusive of embedded OS and services) for the automotive industry. The organization has taken great care to exercise secure software development practices for the firmware Of paramount importance is the ability to defeat attacks aimed at replacing or corrupting running firmware once the vehicle leaves production and is in the field Integrating, which of the following host and OS controls would BEST protect against this threat?

    A. Configure the host to require measured boot with attestation using platform configuration registers extended through the OS and into application space.
    B. Implement out-of-band monitoring to analyze the state of running memory and persistent storage and, in a failure mode, signal a check-engine light condition for the operator.
    C. Perform reverse engineering of the hardware to assess for any implanted logic or other supply chain integrity violations
    D. Ensure the firmware includes anti-malware services that will monitor and respond to any introduction of malicious logic.
    E. Require software engineers to adhere to a coding standard, leverage static and dynamic analysis within the development environment, and perform exhaustive state space analysis before deployment

  • Question 266:

    A member of the software development team has requested advice from the security team to implement a new secure lab for testing malware. Which of the following is the NEXT step that the security team should take?

    A. Purchase new hardware to keep the malware isolated.
    B. Develop a policy to outline what will be required in the secure lab.
    C. Construct a series of VMs to host the malware environment.
    D. Create a proposal and present it to management for approval.

  • Question 267:

    While the code is still in the development environment, a security architect is testing the code stored in the code repository to ensure the top ten OWASP secure coding practices are being followed. Which of the following code analyzers will produce the desired results?

    A. Static
    B. Dynamic
    C. Fuzzer
    D. Peer review

  • Question 268:

    A storage as a service company implements both encryption at rest as well as encryption in transit of customers' data. The security administrator is concerned with the overall security of the encrypted customer data stored by the company servers and wants the development team to implement a solution that will strengthen the customer's encryption key. Which of the following, if implemented, will MOST increase the time an offline password attack against the customers' data would take?

    A. key = NULL ; for (int i=0; i
    B. password = NULL ; for (int i=0; i
    C. password = password + sha(password+salt) + aes256(password+salt)
    D. key = aes128(sha256(password), password))

  • Question 269:

    An enterprise solution requires a central monitoring platform to address the growing networks of various departments and agencies that connect to the network. The current vendor products are not adequate due to the growing number of

    heterogeneous devices.

    Which of the following is the primary concern?

    A. Scalability
    B. Usability
    C. Accountability
    D. Performance

  • Question 270:

    An insurance company has two million customers and is researching the top transactions on its customer portal. It identifies that the top transaction is currently password reset. Due to users not remembering their secret questions, a large number of calls are consequently routed to the contact center for manual password resets. The business wants to develop a mobile application to improve customer engagement in the future, continue with a single factor of authentication, minimize management overhead of the solution, remove passwords, and eliminate to the contact center.

    Which of the following techniques would BEST meet the requirements? (Choose two.)

    A. Magic link sent to an email address
    B. Customer ID sent via push notification
    C. SMS with OTP sent to a mobile number
    D. Third-party social login
    E. Certificate sent to be installed on a device
    F. Hardware tokens sent to customers

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.