CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 321:

    A company's claims processed department has a mobile workforce that receives a large number of email submissions from personal email addresses. An employees recently received an email that approved to be claim form, but it installed malicious software on the employee's laptop when was opened.

    A. Impalement application whitelisting and add only the email client to the whitelist for laptop in the claims processing department.
    B. Required all laptops to connect to the VPN before accessing email.
    C. Implement cloud-based content filtering with sandboxing capabilities.
    D. Install a mail gateway to scan incoming messages and strip attachments before they reach the mailbox.

  • Question 322:

    A security engineer has implemented an internal user access review tool so service teams can baseline user accounts and group memberships. The tool is functional and popular among its initial set of onboarded teams. However, the tool

    has not been built to cater to a broader set of internal teams yet. The engineer has sought feedback from internal stakeholders, and a list of summarized requirements is as follows:

    The tool needs to be responsive so service teams can query it, and then perform an automated response action.

    The tool needs to be resilient to outages so service teams can perform the user access review at any point in time and meet their own SLAs. The tool will become the system-of-record for approval, reapproval, and removal life cycles of group

    memberships and must allow for data retrieval after failure.

    Which of the following need specific attention to meet the requirements listed above? (Choose three.)

    A. Scalability
    B. Latency
    C. Availability
    D. Usability
    E. Recoverability
    F. Maintainability

  • Question 323:

    A financial institution has several that currently employ the following controls:

    1.

    The severs follow a monthly patching cycle.

    2.

    All changes must go through a change management process.

    3.

    Developers and systems administrators must log into a jumpbox to access the servers hosting the data using two-factor authentication.

    4.

    The servers are on an isolated VLAN and cannot be directly accessed from the internal production network.

    An outage recently occurred and lasted several days due to an upgrade that circumvented the approval process. Once the security team discovered an unauthorized patch was installed, they were able to resume operations within an hour. Which of the following should the security administrator recommend to reduce the time to resolution if a similar incident occurs in the future?

    A. Require more than one approver for all change management requests.
    B. Implement file integrity monitoring with automated alerts on the servers.
    C. Disable automatic patch update capabilities on the servers
    D. Enhanced audit logging on the jump servers and ship the logs to the SIEM.

  • Question 324:

    A security administrator is hardening a TrustedSolaris server that processes sensitive data. The data owner has established the following security requirements:

    The data is for internal consumption only and shall not be distributed to outside individuals The systems administrator should not have access to the data processed by the server The integrity of the kernel image is maintained

    Which of the following host-based security controls BEST enforce the data owner's requirements? (Choose three.)

    A. SELinux
    B. DLP
    C. HIDS
    D. Host-based firewall
    E. Measured boot
    F. Data encryption
    G. Watermarking

  • Question 325:

    A company enlists a trusted agent to implement a way to authenticate email senders positively Which of the following is the BEST method for the company to prove Vie authenticity of the message?

    A. issue PlN-enabled hardware tokens
    B. Create a CA win all users
    C. Configure the server to encrypt all messages in transit
    D. include a hash in the body of the message

  • Question 326:

    A company has decided to lower costs by conducting an internal assessment on specific devices and various internal and external subnets. The assessment will be done during regular office hours, but it must not affect any production servers. Which of the following would MOST likely be used to complete the assessment? (Select two.)

    A. Agent-based vulnerability scan
    B. Black-box penetration testing
    C. Configuration review
    D. Social engineering
    E. Malware sandboxing
    F. Tabletop exercise

  • Question 327:

    A security administrator must configure the database server shown below the comply with the four requirements listed. Drag and drop the appropriate ACL that should be configured on the database server to its corresponding requirement. Answer options may be used once or not at all.

    Select and Place:

  • Question 328:

    An application present on the majority of an organization's 1,000 systems is vulnerable to a buffer overflow attack. Which of the following is the MOST comprehensive way to resolve the issue?

    A. Deploy custom HIPS signatures to detect and block the attacks.
    B. Validate and deploy the appropriate patch.
    C. Run the application in terminal services to reduce the threat landscape.
    D. Deploy custom NIPS signatures to detect and block the attacks.

  • Question 329:

    A core router was manipulated by a credentialed bypass to send all network traffic through a secondary router under the control of an unauthorized user connected to the network by WiFi.

    Which of the following would BEST reduce the risk of this attack type occurring?

    A. Implement a strong, complex password policy for user accounts that have access to the core router.
    B. Deploy 802.1X as the NAC system for the WiFi infrastructure.
    C. Add additional port security settings for the switching environment connected to the core router.
    D. Allow access to the core router management interface only through an out-of-band channel.

  • Question 330:

    A security manager wants to implement a policy that will provide management with the ability to monitor employee's activities with minimum impact to productivity. Which of the following policies is BEST suited for this scenario?

    A. Separation of duties
    B. Mandatory vacations
    C. Least privilege
    D. Incident response

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.