CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 341:

    Which of the following would be used in forensic analysis of a compromised Linux system? (Select THREE).

    A. Check log files for logins from unauthorized IPs.
    B. Check /proc/kmem for fragmented memory segments.
    C. Check for unencrypted passwords in /etc/shadow.
    D. Check timestamps for files modified around time of compromise.
    E. Use lsof to determine files with future timestamps.
    F. Use gpg to encrypt compromised data files.
    G. Verify the MD5 checksum of system binaries.
    H. Use vmstat to look for excessive disk I/O.

  • Question 342:

    After several industry comnpetitors suffered data loss as a result of cyebrattacks, the Chief Operating Officer (COO) of a company reached out to the information security manager to review the organization's security stance. As a result of the discussion, the COO wants the organization to meet the following criteria:

    Blocking of suspicious websites Prevention of attacks based on threat intelligence Reduction in spam Identity-based reporting to meet regulatory compliance Prevention of viruses based on signature Protect applications from web-based threats

    Which of the following would be the BEST recommendation the information security manager could make?

    A. Reconfigure existing IPS resources
    B. Implement a WAF
    C. Deploy a SIEM solution
    D. Deploy a UTM solution
    E. Implement an EDR platform

  • Question 343:

    Engineers at a company believe a certain type of data should be protected from competitors, but the data owner insists the information is not sensitive. An information security engineer is implementing controls to secure the corporate SAN. The controls require dividing data into four groups: non-sensitive, sensitive but accessible, sensitive but export-controlled, and extremely sensitive. Which of the following actions should the engineer take regarding the data?

    A. Label the data as extremely sensitive.
    B. Label the data as sensitive but accessible.
    C. Label the data as non-sensitive.
    D. Label the data as sensitive but export-controlled.

  • Question 344:

    An engineer is evaluating the control profile to assign to a system containing PII, financial, and proprietary data.

    Based on the data classification table above, which of the following BEST describes the overall classification?

    A. High confidentiality, high availability
    B. High confidentiality, medium availability
    C. Low availability, low confidentiality
    D. High integrity, low availability

  • Question 345:

    The security configuration management policy states that all patches must undergo testing procedures before being moved into production. The sec... analyst notices a single web application server has been downloading and applying patches during non-business hours without testing. There are no apparent adverse reaction, server functionality does not seem to be affected, and no malware was found after a scan. Which of the following action should the analyst take?

    A. Reschedule the automated patching to occur during business hours.
    B. Monitor the web application service for abnormal bandwidth consumption.
    C. Create an incident ticket for anomalous activity.
    D. Monitor the web application for service interruptions caused from the patching.

  • Question 346:

    A forensics analyst suspects that a breach has occurred. Security logs show the company's OS patch system may be compromised, and it is serving patches that contain a zero-day exploit and backdoor. The analyst extracts an executable file from a packet capture of communication between a client computer and the patch server.

    Which of the following should the analyst use to confirm this suspicion?

    A. File size
    B. Digital signature
    C. Checksums
    D. Anti-malware software
    E. Sandboxing

  • Question 347:

    A Chief Security Officer (CSO) is reviewing the organization's incident response report from a recent incident. The details of the event indicate:

    1.

    A user received a phishing email that appeared to be a report from the organization's CRM tool.

    2.

    The user attempted to access the CRM tool via a fraudulent web page but was unable to access the tool.

    3.

    The user, unaware of the compromised account, did not report the incident and continued to use the CRM tool with the original credentials.

    4.

    Several weeks later, the user reported anomalous activity within the CRM tool.

    5.

    Following an investigation, it was determined the account was compromised and an attacker in another country has gained access to the CRM tool.

    6.

    Following identification of corrupted data and successful recovery from the incident, a lessons learned activity was to be led by the CSO.

    Which of the following would MOST likely have allowed the user to more quickly identify the unauthorized use of credentials by the attacker?

    A. Security awareness training
    B. Last login verification
    C. Log correlation
    D. Time-of-check controls
    E. Time-of-use controls
    F. WAYF-based authentication

  • Question 348:

    Company.org has requested a black-box security assessment be performed on key cyber terrain. On area of concern is the company's SMTP services. The security assessor wants to run reconnaissance before taking any additional action and wishes to determine which SMTP server is Internet-facing.

    Which of the following commands should the assessor use to determine this information?

    A. dnsrecon -d company.org -t SOA
    B. dig company.org mx
    C. nc -v company.org
    D. whois company.org

  • Question 349:

    A security administrator is investigating an incident involving suspicious word processing documents on an employee's computer, which was found powered off in the employee's office. Which of the following tools is BEST suited for extracting full or partial word processing documents from unallocated disk space?

    A. memdump
    B. forenoat
    C. dd
    D. nc

  • Question 350:

    A software development company lost customers recently because of a large number of software issues. These issues were related to integrity and availability defects, including buffer overflows, pointer deferences, and others. Which of the following should the company implement to improve code quality? (Select two).

    A. Development environment access controls
    B. Continuous integration
    C. Code comments and documentation
    D. Static analysis tools
    E. Application containerization
    F. Code obfuscation

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.