CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 291:

    A security assessor is working with an organization to review the policies and procedures associated with managing the organization's virtual infrastructure. During a review of the virtual environment, the assessor determines the organization is using servers to provide more than one primary function, which violates a regulatory requirement. The assessor reviews hardening guides and determines policy allows for this configuration. It would be MOST appropriate for the assessor to advise the organization to:

    A. segment dual-purpose systems on a hardened network segment with no external access
    B. assess the risks associated with accepting non-compliance with regulatory requirements
    C. update system implementation procedures to comply with regulations
    D. review regulatory requirements and implement new policies on any newly provisioned servers

  • Question 292:

    A security engineer is responsible for monitoring company applications for known vulnerabilities. Which of the following is a way to stay current on exploits and information security news?

    A. Update company policies and procedures
    B. Subscribe to security mailing lists
    C. Implement security awareness training
    D. Ensure that the organization vulnerability management plan is up-to-date

  • Question 293:

    A security manager recently categorized an information system. During the categorization effort, the manager determined the loss of integrity of a specific information type would impact business significantly. Based on this, the security manager recommends the implementation of several solutions. Which of the following, when combined, would BEST mitigate this risk? (Select TWO.)

    A. Access control
    B. Whitelisting
    C. Signing
    D. Validation
    E. Boot attestation

  • Question 294:

    A company that all mobile devices be encrypted, commensurate with the full disk encryption scheme of assets, such as workstation, servers, and laptops. Which of the following will MOST likely be a limiting factor when selecting mobile device managers for the company?

    A. Increased network latency
    B. Unavailable of key escrow
    C. Inability to selected AES-256 encryption
    D. Removal of user authentication requirements

  • Question 295:

    A hospital's security team recently determined its network was breached and patient data was accessed by an external entity. The Chief Information Security Officer (CISO) of the hospital approaches the executive management team with this information, reports the vulnerability that led to the breach has already been remediated, and explains the team is continuing to follow the appropriate incident response plan. The executive team is concerned about the hospital's brand reputation and asks the CISO when the incident should be disclosed to the affected patients. Which of the following is the MOST appropriate response?

    A. When it is mandated by their legal and regulatory requirements
    B. As soon as possible in the interest of the patients
    C. As soon as the public relations department is ready to be interviewed
    D. When all steps related to the incident response plan are completed
    E. Upon the approval of the Chief Executive Officer (CEO) to release information to the public

  • Question 296:

    Ann, a CIRT member, is conducting incident response activities on a network that consists of several hundred virtual servers and thousands of endpoints and users. The network generates more than 10,000 log messages per second. The enterprise belong to a large, web-based cryptocurrency startup, Ann has distilled the relevant information into an easily digestible report for executive management . However, she still needs to collect evidence of the intrusion that caused the incident. Which of the following should Ann use to gather the required information?

    A. Traffic interceptor log analysis
    B. Log reduction and visualization tools
    C. Proof of work analysis
    D. Ledger analysis software

  • Question 297:

    A company has hired an external security consultant to conduct a thorough review of all aspects of corporate security. The company is particularly concerned about unauthorized access to its physical offices resulting in network compromises. Which of the following should the consultant recommend be performed to evaluate potential risks?

    A. The consultant should attempt to gain access to physical offices through social engineering and then attempt data exfiltration
    B. The consultant should be granted access to all physical access control systems to review logs and evaluate the likelihood of the threat
    C. The company should conduct internal audits of access logs and employee social media feeds to identify potential insider threats
    D. The company should install a temporary CCTV system to detect unauthorized access to physical offices

  • Question 298:

    A cloud architect needs to isolate the most sensitive portion of the network while maintaining hosting in a public cloud Which of the following configurations can be employed to support this effort?

    A. Create a single-tenancy security group in the public cloud that hosts only similar types of servers
    B. Privatize the cloud by implementing an on-premises instance.
    C. Create a hybrid cloud with an on-premises instance for the most sensitive server types.
    D. Sandbox the servers with the public cloud by server type

  • Question 299:

    An administrator believes that the web servers are being flooded with excessive traffic from time to time. The administrator suspects that these traffic floods correspond to when a competitor makes major announcements. Which of the following should the administrator do to prove this theory?

    A. Implement data analytics to try and correlate the occurrence times.
    B. Implement a honey pot to capture traffic during the next attack.
    C. Configure the servers for high availability to handle the additional bandwidth.
    D. Log all traffic coming from the competitor's public IP addresses.

  • Question 300:

    An organization wants to arm its cybersecurity defensive suite automatically with intelligence on zero-day threats shortly after they emerge. Acquiring tools and services that support which of the following data standards would BEST enable the organization to meet this objective?

    A. XCCDF
    B. OVAL
    C. STIX
    D. CWE
    E. CVE

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.