CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 411:

    Which of the following is the MOST likely reason an organization would decide to use a BYOD policy?

    A. It enables employees to use the devices they are already own, thus reducing costs.
    B. It should reduce the number of help desk and tickets significantly.
    C. It is most secure, as the company owns and completely controls the devices.
    D. It is the least complex method for systems administrator to maintain over time.

  • Question 412:

    When implementing a penetration testing program, the Chief Information Security Officer (CISO) designates different organizational groups within the organization as having different responsibilities, attack vectors, and rules of engagement. First, the CISO designates a team to operate from within the corporate environment. This team is commonly referred to as:

    A. the blue team.
    B. the white team.
    C. the operations team.
    D. the read team.
    E. the development team.

  • Question 413:

    A security administrator is updating corporate policies to respond to an incident involving collusion between two systems administrators that went undetected for more than six months. Which of the following policies would have MOST likely uncovered the collusion sooner? (Choose two.)

    A. Mandatory vacation
    B. Separation of duties
    C. Continuous monitoring
    D. Incident response
    E. Time-of-day restrictions
    F. Job rotation

  • Question 414:

    A security administrator wants to implement two-factor authentication for network switches and routers. The solution should integrate with the company's RADIUS server, which is used for authentication to the network infrastructure devices. The security administrator implements the following:

    1.

    An HOTP service is installed on the RADIUS server.

    2.

    The RADIUS server is configured to require the HOTP service for authentication.

    The configuration is successfully tested using a software supplicant and enforced across all network devices. Network administrators report they are unable to log onto the network devices because they are not being prompted for the second factor.

    Which of the following should be implemented to BEST resolve the issue?

    A. Replace the password requirement with the second factor. Network administrators will enter their username and then enter the token in place of their password in the password field.
    B. Configure the RADIUS server to accept the second factor appended to the password. Network administrators will enter a password followed by their token in the password field.
    C. Reconfigure network devices to prompt for username, password, and a token. Network administrators will enter their username and password, and then they will enter the token.
    D. Install a TOTP service on the RADIUS server in addition to the HOTP service. Use the HOTP on older devices that do not support two-factor authentication. Network administrators will use a web portal to log onto these devices.

  • Question 415:

    An organization is implementing a virtualized thin-client solution for normal user computing and access. During a review of the architecture, concerns were raised that an attacker could gain access to multiple user environments by simply gaining a foothold on a single one with malware. Which of the following reasons BEST explains this?

    A. Malware on one virtual environment could enable pivoting to others by leveraging vulnerabilities in the hypervisor.
    B. A worm on one virtual environment could spread to others by taking advantage of guest OS networking services vulnerabilities.
    C. One virtual environment may have one or more application-layer vulnerabilities, which could allow an attacker to escape that environment.
    D. Malware on one virtual user environment could be copied to all others by the attached network storage controller.

  • Question 416:

    During a recent audit of servers, a company discovered that a network administrator, who required remote access, had deployed an unauthorized remote access application that communicated over common ports already allowed through the firewall. A network scan showed that this remote access application had already been installed on one third of the servers in the company. Which of the following is the MOST appropriate action that the company should take to provide a more appropriate solution?

    A. Implement an IPS to block the application on the network
    B. Implement the remote application out to the rest of the servers
    C. Implement SSL VPN with SAML standards for federation
    D. Implement an ACL on the firewall with NAT for remote access

  • Question 417:

    A security engineer is a new member to a configuration board at the request of management. The company has two new major IT projects starting this year and wants to plan security into the application deployment. The board is primarily concerned with the applications' compliance with federal assessment and authorization standards. The security engineer asks for a timeline to determine when a security assessment of both applications should occur and does not attend subsequent configuration board meetings. If the security engineer is only going to perform a security assessment, which of the following steps in system authorization has the security engineer omitted?

    A. Establish the security control baseline
    B. Build the application according to software development security standards
    C. Review the results of user acceptance testing
    D. Consult with the stakeholders to determine which standards can be omitted

  • Question 418:

    A security manager looked at various logs while investigating a recent security breach in the data center from an external source. Each log below was collected from various security devices compiled from a report through the company's

    security information and event management server.

    Logs:

    Log 1:

    Feb 5 23:55:37.743: %SEC-6-IPACCESSLOGS: list 10 denied 10.2.5.81 3 packets Log 2:

    HTTP://www.company.com/index.php?user=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa

    Log 3:

    Security Error Alert

    Event ID 50: The RDP protocol component X.224 detected an error in the protocol stream and has disconnected the client

    Log 4:

    Encoder oe = new OracleEncoder ();

    String query = "Select user_id FROM user_data WHERE user_name = ` "

    + oe.encode ( req.getParameter("userID") ) + " ` and user_password = ` "

    + oe.encode ( req.getParameter("pwd") ) +" ` ";

    Vulnerabilities

    Buffer overflow

    SQL injection

    ACL

    XSS

    Which of the following logs and vulnerabilities would MOST likely be related to the security breach? (Select TWO).

    A. Log 1
    B. Log 2
    C. Log 3
    D. Log 4
    E. Buffer overflow
    F. ACL
    G. XSS
    H. SQL injection

  • Question 419:

    Ann, a user' brings her laptop to an analyst after noticing it has been operating very slowly. The security analyst examines the laptop and obtains the following output.

    Which of the following will the analyst most likely use NEXT?

    A. Process explorer
    B. Vulnerability scanner
    C. Antivirus
    D. Network enumerator

  • Question 420:

    As part of an organization's compliance program, administrators must complete a hardening checklist and note any potential improvements. The process of noting improvements in the checklist is MOST likely driven by:

    A. the collection of data as part of the continuous monitoring program.
    B. adherence to policies associated with incident response.
    C. the organization's software development life cycle.
    D. changes in operating systems or industry trends.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.