CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 401:

    Drag and drop the cloud deployment model to the associated use-case scenario. Options may be used only once or not at all.

    Select and Place:

  • Question 402:

    A government organization operates and maintains several ICS environments. The categorization of one of the ICS environments led to a moderate baseline. The organization has complied a set of applicable security controls based on this categorization.

    Given that this is a unique environment, which of the following should the organization do NEXT to determine if other security controls should be considered?

    A. Check for any relevant or required overlays.
    B. Review enhancements within the current control set.
    C. Modify to a high-baseline set of controls.
    D. Perform continuous monitoring.

  • Question 403:

    A security architect has designated that a server segment of an enterprise network will require each server to have secure and measured boot capabilities. The architect now wishes to ensure service consumers and peers can verify the integrity of hosted services. Which of the following capabilities must the architect consider for enabling the verification?

    A. Centralized attestation server
    B. Enterprise HSM
    C. vTPM
    D. SIEM

  • Question 404:

    An application has been through a peer review and regression testing and is prepared for release. A security engineer is asked to analyze an application binary to look for potential vulnerabilities prior to wide release. After thoroughly analyzing the application, the engineer informs the developer it should include additional input sanitation in the application to prevent overflows. Which of the following tools did the security engineer MOST likely use to determine this recommendation?

    A. Fuzzer
    B. HTTP interceptor
    C. Vulnerability scanner
    D. SCAP scanner

  • Question 405:

    At 9:00 am each morning, all of the virtual desktops in a VDI implementation become extremely slow and/or unresponsive. The outage lasts for around 10 minutes, after which everything runs properly again. The administrator has traced the problem to a lab of thin clients that are all booted at 9:00 am each morning. Which of the following is the MOST likely cause of the problem and the BEST solution? (Select TWO).

    A. Add guests with more memory to increase capacity of the infrastructure.
    B. A backup is running on the thin clients at 9am every morning.
    C. Install more memory in the thin clients to handle the increased load while booting.
    D. Booting all the lab desktops at the same time is creating excessive I/O.
    E. Install 10-Gb uplinks between the hosts and the lab to increase network capacity.
    F. Install faster SSD drives in the storage system used in the infrastructure.
    G. The lab desktops are saturating the network while booting.
    H. The lab desktops are using more memory than is available to the host systems.

  • Question 406:

    A developer implement the following code snippet.

    Which of the following vulnerabilities does the code snippet resolve?

    A. SQL inject
    B. Buffer overflow
    C. Missing session limit
    D. Information leakage

  • Question 407:

    A new employee is plugged into the network on a BYOD machine but cannot access the network Which of the following must be configured so the employee can connect to the network?

    A. Port security
    B. Firewall
    C. Remote access
    D. VPN

  • Question 408:

    A company is deploying a DIP solution and scanning workstations and network drives for documents that contain potential Pll and payment card data. The results of the first scan are as follows:

    The security learn is unable to identify the data owners for the specific files in a timely manner and does not suspect malicious activity with any of the detected files. Which of the following would address the inherent risk until the data owners can be formally identified?

    A. Move the files from the marketing share to a secured drive.
    B. Search the metadata for each file to locate the file's creator and transfer the files to the personal drive of the listed creator.
    C. Configure the DLP tool to delete the files on the shared drives
    D. Remove the access for the internal audit group from the accounts payable and payroll shares

  • Question 409:

    Following the merger of two large companies the newly combined security team is overwhelmed by the volume of logs flowing from the IT systems The company's data retention schedule complicates the issue by requiring detailed logs to be collected and available for months Which of the following designs BEST meets the company's security and retention requirement?

    A. Forward logs to both a SlEM and a cheaper longer-term storage and then delete logs from the SlEM after 14 days
    B. Reduce the log volume by disabling logging of routine maintenance activities or failed authentication attempts
    C. Send logs to a SlEM that correlates security data and store only the alerts and relevant data arising from that system.
    D. Maintain both companies' logging and SlEM solutions separately but merge the resulting alerts and reports.

  • Question 410:

    An organization is struggling to differentiate threats from normal traffic and access to systems. A security engineer has been asked to recommend a system that will aggregate data and provide metrics that will assist in identifying malicious actors or other anomalous activity throughout the environment. Which of the following solutions should the engineer recommend?

    A. Web application firewall
    B. SIEM
    C. IPS
    D. UTM
    E. File integrity monitor

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.