CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 271:

    A remote user reports the inability to authenticate to the VPN concentrator. During troubleshooting, a security administrator captures an attempted authentication and discovers the following being presented by the user's VPN client:

    Which of the following BEST describes the reason the user is unable to connect to the VPN service?

    A. The user's certificate is not signed by the VPN service provider
    B. The user's certificate has been compromised and should be revoked.
    C. The user's certificate was not created for VPN use
    D. The user's certificate was created using insecure encryption algorithms

  • Question 272:

    An organization is considering the use of a thin client architecture as it moves to a cloud-hosted environment. A security analyst is asked to provide thoughts on the security advantages of using thin clients and virtual workstations. Which of the following are security advantages of the use of this combination of thin clients and virtual workstations?

    A. Malicious insiders will not have the opportunity to tamper with data at rest and affect the integrity of the system.
    B. Thin client workstations require much less security because they lack storage and peripherals that can be easily compromised, and the virtual workstations are protected in the cloud where security is outsourced.
    C. All thin clients use TPM for core protection, and virtual workstations use vTPM for core protection with both equally ensuring a greater security advantage for a cloud-hosted environment.
    D. Malicious users will have reduced opportunities for data extractions from their physical thin client workstations, this reducing the effectiveness of local attacks.

  • Question 273:

    A business is growing and starting to branch out into other locations. In anticipation of opening an office in a different country, the Chief Information Security Officer (CISO) and legal team agree they need to meet the following criteria regarding data to open the new office:

    Store taxation-related documents for five years Store customer addresses in an encrypted format Destroy customer information after one year Keep data only in the customer's home country

    Which of the following should the CISO implement to BEST meet these requirements? (Choose three.)

    A. Capacity planning policy
    B. Data retention policy
    C. Data classification standard
    D. Legal compliance policy
    E. Data sovereignty policy
    F. Backup policy
    G. Acceptable use policy
    H. Encryption standard

  • Question 274:

    Following a recent network intrusion, a company wants to determine the current security awareness of all of its employees. Which of the following is the BEST way to test awareness?

    A. Conduct a series of security training events with comprehensive tests at the end
    B. Hire an external company to provide an independent audit of the network security posture
    C. Review the social media of all employees to see how much proprietary information is shared
    D. Send an email from a corporate account, requesting users to log onto a website with their enterprise account

  • Question 275:

    The helpdesk is receiving multiple calls about slow and intermittent Internet access from the finance department. The following information is compiled: Caller 1, IP 172.16.35.217, NETMASK 255.255.254.0 Caller 2, IP 172.16.35.53, NETMASK 255.255.254.0 Caller 3, IP 172.16.35.173, NETMASK 255.255.254.0 All callers are connected to the same switch and are routed by a router with five built-in interfaces. The upstream router interface's MAC is 00-01-42-32-ab-1a A packet capture shows the following: 09:05:15.934840 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a) 09:06:16.124850 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a) 09:07:25.439811 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a) 09:08:10.937590 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2305, seq 1, length 65534 09:08:10.937591 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2306, seq 2, length 65534 09:08:10.937592 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2307, seq 3, length 65534 Which of the following is occurring on the network?

    A. A man-in-the-middle attack is underway on the network.
    B. An ARP flood attack is targeting at the router.
    C. The default gateway is being spoofed on the network.
    D. A denial of service attack is targeting at the router.

  • Question 276:

    A security administrator is shown the following log excerpt from a Unix system: 2013 Oct 10 07:14:57 web14 sshd[1632]: Failed password for root from 198.51.100.23 port 37914 ssh2 2013 Oct 10 07:14:57 web14 sshd[1635]: Failed password for root from 198.51.100.23 port 37915 ssh2 2013 Oct 10 07:14:58 web14 sshd[1638]: Failed password for root from 198.51.100.23 port 37916 ssh2 2013 Oct 10 07:15:59 web14 sshd[1640]: Failed password for root from 198.51.100.23 port 37918 ssh2 2013 Oct 10 07:16:00 web14 sshd[1641]: Failed password for root from 198.51.100.23 port 37920 ssh2 2013 Oct 10 07:16:00 web14 sshd[1642]: Successful login for root from 198.51.100.23 port 37924 ssh2 Which of the following is the MOST likely explanation of what is occurring and the BEST immediate response? (Select TWO).

    A. An authorized administrator has logged into the root account remotely.
    B. The administrator should disable remote root logins.
    C. Isolate the system immediately and begin forensic analysis on the host.
    D. A remote attacker has compromised the root account using a buffer overflow in sshd.
    E. A remote attacker has guessed the root password using a dictionary attack.
    F. Use iptables to immediately DROP connections from the IP 198.51.100.23.
    G. A remote attacker has compromised the private key of the root account.
    H. Change the root password immediately to a password not found in a dictionary.

  • Question 277:

    A company has noticed recently that its corporate information has ended up on an online forum. An investigation has identified that internal employees are sharing confidential corporate information on a daily basis. Which of the following are the MOST effective security controls that can be implemented to stop the above problem? (Select TWO).

    A. Implement a URL filter to block the online forum
    B. Implement NIDS on the desktop and DMZ networks
    C. Security awareness compliance training for all employees
    D. Implement DLP on the desktop, email gateway, and web proxies
    E. Review of security policies and procedures

  • Question 278:

    A Chief Information Security Officer (CISO) is working with a consultant to perform a gap assessment prior to an upcoming audit. It is determined during the assessment that the organization lacks controls to effectively assess regulatory compliance by third-party service providers. Which of the following should be revised to address this gap?

    A. Privacy policy
    B. Work breakdown structure
    C. Interconnection security agreement
    D. Vendor management plan
    E. Audit report

  • Question 279:

    Several days after deploying an MDM for smartphone control, an organization began noticing anomalous behavior across the enterprise Security analysts observed the following:

    1.

    Unauthorized certificate issuance

    2.

    Access to mutually authenticated resources utilizing valid but unauthorized certificates

    3.

    Granted access to internal resources via the SSL VPN

    To address the immediate problem security analysts revoked the erroneous certificates. Which of the following describes the MOST likely root cause of the problem and offers a solution?

    A. The VPN and web resources are configured with too weak a cipher suite and should be rekeyed to support AES 256 in GCM and ECC for digital signatures and key exchange
    B. A managed mobile device is rooted exposing its keystore and the MDM should be reconfigured to wipe these devices and disallow access to corporate resources
    C. SCEP is configured insecurely which should be enabled for device onboarding against a PKI for mobile-exclusive use
    D. The CA is configured to sign any received CSR from mobile users and should be reconfigured to permit CSR signings only from domain administrators.

  • Question 280:

    After a large organization has completed the acquisition of a smaller company, the smaller company must implement new host-based security controls to connect its employees' devices to the network. Given that the network requires 802.1X EAP-PEAP to identify and authenticate devices, which of the following should the security administrator do to integrate the new employees devices into the network securely?

    A. Distribute a NAC client and use the client to push the company's private key to all the new devices.
    B. Distribute the device connection policy and a unique public/private key pair to each new employee's device.
    C. Install a self-signed SSL certificate on the company's RADIUS server and distribute the certificate's public key to all new client devices.
    D. Install an 802.1X supplicant on all new devices and let each device generate a self- signed certificate to use for network access.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.