CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 301:

    An engineer maintains a corporate-owned mobility infrastructure, and the organization requires that all web browsing using corporate-owned resources be monitored. Which of the following would allow the organization to meet its requirement? (Choose two.)

    A. Exempt mobile devices from the requirement, as this will lead to privacy violations
    B. Configure the devices to use an always-on IPSec VPN
    C. Configure all management traffic to be tunneled into the enterprise via TLS
    D. Implement a VDI solution and deploy supporting client apps to devices
    E. Restrict application permissions to establish only HTTPS connections outside of the enterprise boundary

  • Question 302:

    When reviewing KRIs of the email security appliance with the Chief Information Security Officer (CISO) of an insurance company, the security engineer notices the following:

    Which of the following measures should the security engineer take to ensure PII is not intercepted in transit while also preventing interruption to business?

    A. Quarantine emails sent to external domains containing PII and release after inspection.
    B. Prevent PII from being sent to domains that allow users to sign up for free webmail.
    C. Enable transport layer security on all outbound email communications and attachments.
    D. Provide security awareness training regarding transmission of PII.

  • Question 303:

    Within change management, which of the following ensures functions are earned out by multiple employees?

    A. Least privilege
    B. Mandatory vacation
    C. Separation of duties
    D. Job rotation

  • Question 304:

    A development team releases updates to an application regularly. The application is compiled with several standard open-source security products that require a minimum version for compatibility. During the security review portion of the development cycle, which of the following should be done to minimize possible application vulnerabilities?

    A. The developers should require an exact version of the open-source security products, preventing the introduction of new vulnerabilities.
    B. The application development team should move to an Agile development approach to identify security concerns faster
    C. The change logs for the third-party libraries should be reviewed for security patches, which may need to be included in the release.
    D. The application should eliminate the use of open-source libraries and products to prevent known vulnerabilities from being included.

  • Question 305:

    A company has entered into a business agreement with a business partner for managed human resources services. The Chief Information Security Officer (CISO) has been asked to provide documentation that is required to set up a business-to-business VPN between the two organizations.

    Which of the following is required in this scenario?

    A. ISA
    B. BIA
    C. SLA
    D. RA

  • Question 306:

    An organization is evaluating options related to moving organizational assets to a cloud-based environment using an IaaS provider. One engineer has suggested connecting a second cloud environment within the organization's existing facilities to capitalize on available datacenter space and resources. Other project team members are concerned about such a commitment of organizational assets, and ask the Chief Security Officer (CSO) for input. The CSO explains that the project team should work with the engineer to evaluate the risks associated with using the datacenter to implement:

    A. a hybrid cloud.
    B. an on-premises private cloud.
    C. a hosted hybrid cloud.
    D. a private cloud.

  • Question 307:

    A company is developing requirements for a customized OS build that will be used in an embedded environment. The company procured hardware that is capable of reducing the likelihood of successful buffer overruns while executables are processing. Which of the following capabilities must be included for the OS to take advantage of this critical hardware-based countermeasure?

    A. Application whitelisting
    B. NX/XN bit
    C. ASLR
    D. TrustZone
    E. SCP

  • Question 308:

    An administrator is working with management to develop policies related to the use of the cloud-based resources that contain corporate data. Management plans to require some control over organizational data stored on personal devices, such as tablets. Which of the following controls would BEST support management's policy?

    A. MDM
    B. Sandboxing
    C. Mobile tokenization
    D. FDE
    E. MFA

  • Question 309:

    While traveling to another state, the Chief Financial (CFO) forgot to submit payroll for the company. The CFO quickly gained to the corporate through the high-speed wireless network provided by the hotel and completed the desk. Upon returning from the business trip, the CFO was told no one received their weekly pay due to a malware on attack on the system. Which of the following is the MOST likely of the security breach?

    A. The security manager did not enforce automate VPN connection.
    B. The company's server did not have endpoint security enabled.
    C. The hotel and did require a wireless password to authenticate.
    D. The laptop did not have the host-based firewall properly configured.

  • Question 310:

    A developer emails the following output to a security administrator for review:

    Which of the following tools might the security administrator use to perform further security assessment of this issue?

    A. Port scanner
    B. Vulnerability scanner
    C. Fuzzer
    D. HTTP interceptor

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.