CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 371:

    A security analyst is investigating a series of suspicious emails by employees to the security team. The email appear to come from a current business partner and do not contain images or URLs. No images or URLs were stripped from the message by the security tools the company uses instead, the emails only include the following in plain text.

    Which of the following should the security analyst perform?

    A. Contact the security department at the business partner and alert them to the email event.
    B. Block the IP address for the business partner at the perimeter firewall.
    C. Pull the devices of the affected employees from the network in case they are infected with a zero-day virus.
    D. Configure the email gateway to automatically quarantine all messages originating from the business partner.

  • Question 372:

    A company is outsourcing to an MSSP that performs managed detection and response services. The MSSP requires a server to be placed inside the network as a log aggregator and allows remote access to MSSP analysts. Critical devices send logs to the log aggregator, where data is stored for 12 months locally before being archived to a multitenant cloud The data is then sent from the log aggregator to a public IP address in the MSSP's datacenter for analysis. A security engineer is concerned about the secunty of the solution and notes the following

    1.

    The critical devices send cleartext logs to the aggregator.

    2.

    The log aggregator utilizes full disk encryption.

    3.

    The log aggregator sends to the analysis server via port 80.

    4.

    MSSP analysts utilize an SSL VPN with MFA to access the log aggregator remotely.

    5.

    The data is compressed and encrypted prior to being archived in the cloud.

    Which of the following should be the secunty engineer's GREATEST concern?

    A. Hardware vulnerabilities introduced by the log aggregator server.
    B. Network bridging from a remote access VPN.
    C. Encryption of data in transit.
    D. Multitenancy and data remnants in the cloud.

  • Question 373:

    An organization's Chief Financial Officer (CFO) was the target of several different social engineering attacks recently. The CFO has subsequently worked closely with the Chief Information Security Officer (CISO) to increase awareness of what attacks may look like. An unexpected email arrives in the CFO's inbox from a familiar name with an attachment. Which of the following should the CISO task a security analyst with to determine whether or not the attachment is safe?

    A. Place it in a malware sandbox.
    B. Perform a code review of the attachment.
    C. Conduct a memory dump of the CFO's PC.
    D. Run a vulnerability scan on the email server.

  • Question 374:

    An organization based in the United States is planning to expand its operations into the European market later in the year Legal counsel is exploring the additional requirements that must be established as a result of the expansion. The BEST course of action would be to:

    A. revise the employee provisioning and deprovisioning procedures
    B. complete a quantitative risk assessment
    C. draft a memorandum of understanding
    D. complete a security questionnaire focused on data privacy.

  • Question 375:

    A system administrator recently conducted a vulnerability scan of the internet. Subsequently, the organization was successfully attacked by an adversary. Which of the following in the MOST likely explanation for why the organization network was compromised?

    A. There was a false positive since the network was fully patched.
    B. The system administrator did not perform a full system sun.
    C. The systems administrator performed a credentialed scan.
    D. The vulnerability database was not updated.

  • Question 376:

    A government contracting company issues smartphones to employees to enable access to corporate resources. Several employees will need to travel to a foreign country for business purposes and will require access to their phones. However, the company recently received intelligence that its intellectual property is highly desired by the same country's government. Which of the following MDM configurations would BEST reduce the risk of compromise while on foreign soil?

    A. Disable firmware OTA updates.
    B. Disable location services.
    C. Disable push notification services.
    D. Disable wipe

  • Question 377:

    The helpdesk manager wants to find a solution that will enable the helpdesk staff to better serve company employees who call with computer-related problems. The helpdesk staff is currently unable to perform effective troubleshooting and relies on callers to describe their technology problems. Given that the helpdesk staff is located within the company headquarters and 90% of the callers are telecommuters, which of the following tools should the helpdesk manager use to make the staff more effective at troubleshooting while at the same time reducing company costs? (Select TWO).

    A. Web cameras
    B. Email
    C. Instant messaging
    D. BYOD
    E. Desktop sharing
    F. Presence

  • Question 378:

    An organization is integrating an ICS and wants to ensure the system is cyber resilient. Unfortunately, many of the specialized components are legacy systems that cannot be patched. The existing enterprise consists of mission-critical systems that require 99.9% uptime. To assist in the appropriate design of the system given the constraints, which of the following MUST be assumed?

    A. Vulnerable components
    B. Operational impact due to attack
    C. Time criticality of systems
    D. Presence of open-source software

  • Question 379:

    A security engineer is attempting to convey the importance of including job rotation in a company's standard security policies. Which of the following would be the BEST justification?

    A. Making employees rotate through jobs ensures succession plans can be implemented and prevents single point of failure.
    B. Forcing different people to perform the same job minimizes the amount of time malicious actions go undetected by forcing malicious actors to attempt collusion between two or more people.
    C. Administrators and engineers who perform multiple job functions throughout the day benefit from being cross-trained in new job areas.
    D. It eliminates the need to share administrative account passwords because employees gain administrative rights as they rotate into a new job area.

  • Question 380:

    A software development manager is running a project using agile development methods. The company cybersecurity engineer has noticed a high number of vulnerabilities have been making it into production code on the project.

    Which of the following methods could be used in addition to an integrated development environment to reduce the severity of the issue?

    A. Conduct a penetration test on each function as it is developed
    B. Develop a set of basic checks for common coding errors
    C. Adopt a waterfall method of software development
    D. Implement unit tests that incorporate static code analyzers

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.