CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 351:

    The Chief Executive Officers (CEOs) from two different companies are discussing the highly sensitive prospect of merging their respective companies together. Both have invited their Chief Information Officers (CIOs) to discern how they can securely and digitaly communicate, and the following criteria are collectively determined:

    Must be encrypted on the email servers and clients Must be OK to transmit over unsecure Internet connections

    Which of the following communication methods would be BEST to recommend?

    A. Force TLS between domains.
    B. Enable STARTTLS on both domains.
    C. Use PGP-encrypted emails.
    D. Switch both domains to utilize DNSSEC.

  • Question 352:

    A security tester is performing a black-box assessment of an RFID access control system. The tester has a handful of RFID tags and is able to access the reader. However the tester cannot disassemble the reader because it is in use by the

    company.

    Which of the following shows the steps the tester should take to assess the RFID access control system in the correct order?

    A. 1 Attempt to eavesdrop and replay RFID communications. 2. Determine the protocols being used between the tag and the reader. 3. Retrieve the RFID tag identifier and manufacturer details. 4. Take apart an RFID tag and analyze the chip.
    B. 1. Determine the protocols being used between the tag and the reader. 2. Take apart an RFID tag and analyze the chip. 3. Retrieve the RFID tag identifier and manufacturer details. 4. Attempt to eavesdrop and replay RFID communications.
    C. 1. Retrieve the RFID tag identifier and manufacturer details. 2. Determine the protocols is being used between the tag and the reader. 3 Attempt to eavesdrop and replay RFID communications. 4. Take apart an RFID tag and analyze the chip.
    D. 1 Take apart an RFID tag and analyze the chip. 2. Retrieve the RFID tag identifier and manufacturer details. 3. Determine the protocols being used between the tag and the reader. 4. Attempt to eavesdrop and replay RFID communications.

  • Question 353:

    Developers are working on anew feature to add to a social media platform. Thew new feature involves users uploading pictures of what they are currently doing. The data privacy officer (DPO) is concerned about various types of abuse that might occur due to this new feature. The DPO state the new feature cannot be released without addressing the physical safety concerns of the platform's users. Which of the following controls would BEST address the DPO's concerns?

    A. Increasing blocking options available to the uploader
    B. Adding a one-hour delay of all uploaded photos
    C. Removing all metadata in the uploaded photo file
    D. Not displaying to the public who uploaded the photo
    E. Forcing TLS for all connections on the platform

  • Question 354:

    A systems engineer is reviewing output from a web application vulnerability scan. The engineer has determined data is entenng the application from an untrusted source and is being used to construct a query dynamically. Which of the following code snippets would BEST protect the application against an SQL injection attack?

    A. String input = request.getParameter ("SeqNo"); String characterPattern = "[0-9a0zA-Z] If (! input. Matches (characterPattern)) { out.println ("Invalid Input"); }
    B. Cinput type= "text" maxlength= "30" name= "ecsChangePwdForm" size= "40" readonly= "true" value= ''/>
    C. catch (Exception e) { if (log.isDebugEnabled()) log.debug (context, EVENTS.ADHOC, "Caught InvalidGSMException Exception —andquot; + e.toString() ); }

  • Question 355:

    A laptop is recovered a few days after it was stolen.

    Which of the following should be verified during incident response activities to determine the possible impact of the incident?

    A. Full disk encryption status
    B. TPM PCR values
    C. File system integrity
    D. Presence of UEFI vulnerabilities

  • Question 356:

    Which of the following is the GREATEST security concern with respect to BYOD?

    A. The filtering of sensitive data out of data flows at geographic boundaries.
    B. Removing potential bottlenecks in data transmission paths.
    C. The transfer of corporate data onto mobile corporate devices.
    D. The migration of data into and out of the network in an uncontrolled manner.

  • Question 357:

    A company has gone through a round of phishing attacks. More than 200 users have had their workstation infected because they clicked on a link in an email. An incident analysis has determined an executable ran and compromised the administrator account on each workstation. Management is demanding the information security team prevent this from happening again. Which of the following would BEST prevent this from happening again?

    A. Antivirus
    B. Patch management
    C. Log monitoring
    D. Application whitelisting
    E. Awareness training

  • Question 358:

    A security engineer is designing a system in which offshore, outsourced staff can push code from the development environment to the production environment securely. The security engineer is concerned with data loss, while the business does not want to slow down its development process. Which of the following solutions BEST balances security requirements with business need?

    A. Set up a VDI environment that prevents copying and pasting to the local workstations of outsourced staff members
    B. Install a client-side VPN on the staff laptops and limit access to the development network
    C. Create an IPSec VPN tunnel from the development network to the office of the outsourced staff
    D. Use online collaboration tools to initiate workstation-sharing sessions with local staff who have access to the development network

  • Question 359:

    Which of the following may indicate a configuration item has reached end-of-life?

    A. The device will no longer turn on and indicated an error.
    B. The vendor has not published security patches recently.
    C. The object has been removed from the Active Directory.
    D. Logs show a performance degradation of the component.

  • Question 360:

    A security consultant is improving the physical security of a sensitive site and takes pictures of the unbranded building to include in the report. Two weeks later, the security consultant misplaces the phone, which only has one hour of charge left on it. The person who finds the phone removes the MicroSD card in an attempt to discover the owner to return it. The person extracts the following data from the phone and EXIF data from some files: DCIM Images folder Audio books folder Torrentz

    My TAX.xls Consultancy HR Manual.doc Camera: SM-G950F

    Exposure time: 1/60s Location: 3500 Lacey Road USA Which of the following BEST describes the security problem?

    A. MicroSD in not encrypted and also contains personal data.
    B. MicroSD contains a mixture of personal and work data.
    C. MicroSD in not encrypted and contains geotagging information.
    D. MicroSD contains pirated software and is not encrypted.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.