CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 361:

    A company is acquiring incident response and forensic assistance from a managed security service provider in the event of a data breach. The company has selected a partner and must now provide required documents to be reviewed and evaluated.

    Which of the following documents would BEST protect the company and ensure timely assistance? (Choose two.)

    A. RA
    B. BIA
    C. NDA
    D. RFI
    E. RFQ
    F. MSA

  • Question 362:

    An organization has decided to reduce labor costs by outsourcing back office processing of credit applications to a provider located in another country. Data sovereignty and privacy concerns raised by the security team resulted in the third-party provider only accessing and processing the data via remote desktop sessions. To facilitate communications and improve productivity, staff at the third party has been provided with corporate email accounts that are only accessible via the remote desktop sessions. Email forwarding is blocked and staff at the third party can only communicate with staff within the organization. Which of the following additional controls should be implemented to prevent data loss? (Select THREE).

    A. Implement hashing of data in transit
    B. Session recording and capture
    C. Disable cross session cut and paste
    D. Monitor approved credit accounts
    E. User access audit reviews
    F. Source IP whitelisting

  • Question 363:

    A mature organization with legacy information systems has incorporated numerous new processes and dependencies to manage security as its networks and infrastructure are modernized. The Chief Information Office has become increasingly frustrated with frequent releases, stating that the organization needs everything to work completely, and the vendor should already have those desires built into the software product. The vendor has been in constant communication with personnel and groups within the organization to understand its business process and capture new software requirements from users. Which of the following methods of software development is this organization's configuration management process using?

    A. Agile
    B. SDL
    C. Waterfall
    D. Joint application development

  • Question 364:

    A company is in the process of implementing a new front end user interface for its customers, the goal is to provide them with more self-service functionality. The application has been written by developers over the last six months and the project is currently in the test phase.

    Which of the following security activities should be implemented as part of the SDL in order to provide the MOST security coverage over the solution? (Select TWO).

    A. Perform unit testing of the binary code
    B. Perform code review over a sampling of the front end source code
    C. Perform black box penetration testing over the solution
    D. Perform grey box penetration testing over the solution
    E. Perform static code review over the front end source code

  • Question 365:

    A system worth $100,000 has an exposure factor of eight percent and an ARO of four. Which of the following figures is the system's SLE?

    A. $2,000
    B. $8,000
    C. $12,000
    D. $32,000

  • Question 366:

    During a routine network scan, a security administrator discovered an unidentified service running on a new embedded and unmanaged HVAC controller, which is used to monitor the company's datacenter

    Port state

    161/UDP open

    162/UDP open

    163/TCP open

    The enterprise monitoring service requires SNMP and SNMPTRAP connectivity to operate. Which of the following should the security administrator implement to harden the system?

    A. Patch and restart the unknown services.
    B. Segment and firewall the controller's network
    C. Disable the unidentified service on the controller.
    D. Implement SNMPv3 to secure communication.
    E. Disable TCP/UDP PORTS 161 THROUGH 163

  • Question 367:

    A consultant is hired to perform a passive vulnerability assessment of a company to determine what information might be collected about the company and its employees. The assessment will be considered successful if the consultant can discover the name of one of the IT administrators. Which of the following is MOST likely to produce the needed information?

    A. Whois
    B. DNS enumeration
    C. Vulnerability scanner
    D. Fingerprinting

  • Question 368:

    A Chief Information Security Officer (CISO is reviewing and revising system configuration and hardening guides that were developed internally and have been used several years to secure the organization's systems.

    The CISO knows improvements can be made to the guides.

    Which of the following would be the BEST source of reference during the revision process?

    A. CVE database
    B. Internal security assessment reports
    C. Industry-accepted standards
    D. External vulnerability scan reports
    E. Vendor-specific implementation guides

  • Question 369:

    An architect was recently hired by a power utility to increase the security posture of the company's power generation and distribution sites. Upon review, the architect identifies legacy hardware with highly vulnerable and unsupported software driving critical operations. These systems must exchange data with each other, be highly synchronized, and pull from the Internet time sources. Which of the following architectural decisions would BEST reduce the likelihood of a successful attack without harming operational capability? (Choose two.)

    A. Isolate the systems on their own network
    B. Install a firewall and IDS between systems and the LAN
    C. Employ own stratum-0 and stratum-1 NTP servers
    D. Upgrade the software on critical systems
    E. Configure the systems to use government-hosted NTP servers

  • Question 370:

    A security administrator receives reports that several workstations are unable to access resources within one network segment. A packet capture shows the segment is flooded with ICMPv6 traffic from the source fe80::21ae;4571:42ab:1fdd and for the destination ff02::1.

    Which of the following should the security administrator integrate into the network to help prevent this from occurring?

    A. Raise the dead peer detection interval to prevent the additional network chatter
    B. Deploy honeypots on the network segment to identify the sending machine.
    C. Ensure routers will use route advertisement guards.
    D. Deploy ARP spoofing prevention on routers and switches.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.