CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 391:

    A security analyst is attempting to identify code that is vulnerable to butler and integer overflow attacks. Which of the following code snippets is safe from these types of attacks?

    A. Option A
    B. Option B
    C. Option C
    D. Option D

  • Question 392:

    The Chief Information Security Officer (CISO) of an organization is concerned with the transmission of cleartext authentication information across the enterprise. A security assessment has been performed and has identified the use of ports

    80. 389. and 3268. Which of the following solutions would BEST address the CISO's concerns?

    A. Disable the ports that are determined to contain authentication information
    B. Force HTTPS. enable LDAPS. and disable cleartext global catalog communication.
    C. Deploy a VPN between networks that transmits authentication information via cleartext
    D. Proxy HTTP traffic and migrate to a more secure directory service

  • Question 393:

    A software development firm wants to validate the use of standard libraries as part of the software development process Each developer performs unit testing prior to committing changes to the code repository. Which of the following activities would be BEST to perform after a commit but before the creation of a branch?

    A. Static analysis
    B. Heuristic analysis
    C. Dynamic analysis
    D. Web application vulnerability scanning
    E. Penetration testing

  • Question 394:

    A company makes consumer health devices and needs to maintain strict confidentiality of unreleased product designs Recently unauthorized photos of products still in development have been for sale on the dark web. The Chief Information Security Officer (CISO) suspects an insider threat, but the team that uses the secret outdoor testing area has been vetted many times and nothing suspicious has been found Which of the following is the MOST likely cause of the unauthorized photos?

    A. The location of the testing facility was discovered by analyzing fitness device information the test engineers posted on a website
    B. One of the test engineers is working for a competitor and covertly installed a RAT on the marketing department's servers
    C. The company failed to implement least privilege on network devices, and a hacktivist published stolen public relations photos
    D. Pre-release marketing materials for a single device were accidentally left in a public location

  • Question 395:

    A creative services firm has a limited security budget and staff. Due to its business model, the company sends and receives a high volume of files every day through the preferred method defined by its customers. These include email, secure file transfers, and various cloud service providers. Which of the following would BEST reduce the risk of malware infection while meeting the company's resource requirements and maintaining its current workflow?

    A. Configure a network-based intrusion prevention system
    B. Contract a cloud-based sandbox security service.
    C. Enable customers to send and receive files via SFTP
    D. Implement appropriate DLP systems with strict policies.

  • Question 396:

    A project manager is working with a software development group to collect and evaluate user stories related to the organization's internally designed CRM tool. After defining requirements, the project manager would like to validate the developer's interpretation and understanding of the user's request. Which of the following would BEST support this objective?

    A. Peer review
    B. Design review
    C. Scrum
    D. User acceptance testing
    E. Unit testing

  • Question 397:

    A technician receives the following security alert from the firewall's automated system:

    Match_Time: 10/10/16 16:20:43

    Serial: 002301028176

    Device_name: COMPSEC1

    Type: CORRELATION

    Scrusex: domain\samjones

    Scr: 10.50.50.150

    Object_name: beacon detection

    Object_id: 6005

    Category: compromised-host

    Severity: medium

    Evidence: host repeatedly visited a dynamic DNS domain (17 time)

    After reviewing the alert, which of the following is the BEST analysis?

    A. the alert is a false positive because DNS is a normal network function.
    B. this alert indicates a user was attempting to bypass security measures using dynamic DNS.
    C. this alert was generated by the SIEM because the user attempted too many invalid login attempts.
    D. this alert indicates an endpoint may be infected and is potentially contacting a suspect host.

  • Question 398:

    An SQL database is no longer accessible online due to a recent security breach. An investigation reveals that unauthorized access to the database was possible due to an SQL injection vulnerability. To prevent this type of breach in the future, which of the following security controls should be put in place before bringing the database back online? (Choose two.)

    A. Secure storage policies
    B. Browser security updates
    C. Input validation
    D. Web application firewall
    E. Secure coding standards
    F. Database activity monitoring

  • Question 399:

    An engineer wants to assess the OS security configurations on a company's servers. The engineer has downloaded some files to orchestrate configuration checks When the engineer opens a file in a text editor, the following excerpt appears: Which of the following capabilities would a configuration compliance checker need to support to interpret this file?

    A. Nessus
    B. Swagger file
    C. SCAP
    D. Netcat
    E. WSDL

  • Question 400:

    A security administrator notices the following line in a server's security log:

    ') + "';

    The administrator is concerned that it will take the developer a lot of time to fix the application that is running on the server. Which of the following should the security administrator implement to prevent this particular attack?

    A. WAF
    B. Input validation
    C. SIEM
    D. Sandboxing
    E. DAM

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.