CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 431:

    A company is repeatedly being breached by hackers who valid credentials. The company's Chief information Security Officer (CISO) has installed multiple controls for authenticating users, including biometric and token-based factors. Each successive control has increased overhead and complexity but has failed to stop further breaches. An external consultant is evaluating the process currently in place to support the authentication controls. Which of the following recommendation would MOST likely reduce the risk of unauthorized access?

    A. Implement strict three-factor authentication.
    B. Implement least privilege policies
    C. Switch to one-time or all
    D. Strengthen identify-proofing procedures

  • Question 432:

    A security analyst is trying to identify the source of a recent data loss incident The analyst has reviewed all the logs for the time surrounding the incident and identified all the assets on the network at the time of the data loss. The analyst suspects the key to finding the source was obfuscated in an application.

    Which of the following tools should the analyst use NEXT?

    A. Software decompiler
    B. Network enumerator
    C. Log reduction and analysis tool
    D. Static code analysis

  • Question 433:

    Designing a system in which only information that is essential for a particular job task is allowed to be viewed can be accomplished successfully by using:

    A. mandatory vacations.
    B. job rotations
    C. role-based access control
    D. discretionary access
    E. separation of duties

  • Question 434:

    A database administrator is required to adhere to and implement privacy principles when executing daily tasks. A manager directs the administrator to reduce the number of unique instances of PII stored within an organization's systems to the greatest extent possible. Which of the following principles is being demonstrated?

    A. Administrator accountability
    B. PII security
    C. Record transparency
    D. Data minimization

  • Question 435:

    A large company is preparing to merge with a smaller company. The smaller company has been very profitable, but the smaller company's main applications were created in-house. Which of the following actions should the large company's security administrator take in preparation for the merger?

    A. A review of the mitigations implemented from the most recent audit findings of the smaller company should be performed.
    B. An ROI calculation should be performed to determine which company's application should be used.
    C. A security assessment should be performed to establish the risks of integration or co-existence.
    D. A regression test should be performed on the in-house software to determine security risks associated with the software.

  • Question 436:

    Ann, a member of the finance department at a large corporation, has submitted a suspicious email she received to the information security team. The team was not expecting an email from Ann, and it contains a PDF file inside a ZIP compressed archive. The information security learn is not sure which files were opened. A security team member uses an air-gapped PC to open the ZIP and PDF, and it appears to be a social engineering attempt to deliver an exploit.

    Which of the following would provide greater insight on the potential impact of this attempted attack?

    A. Run an antivirus scan on the finance PC.
    B. Use a protocol analyzer on the air-gapped PC.
    C. Perform reverse engineering on the document.
    D. Analyze network logs for unusual traffic.
    E. Run a baseline analyzer against the user's computer.

  • Question 437:

    The risk manager has requested a security solution that is centrally managed, can easily be updated, and protects end users' workstations from both known and unknown malicious attacks when connected to either the office or home network. Which of the following would BEST meet this requirement?

    A. HIPS
    B. UTM
    C. Antivirus
    D. NIPS
    E. DLP

  • Question 438:

    A security engineer on a large enterprise network needs to schedule maintenance within a fixed window of time. A total outage period of four hours is permitted for servers. Workstations can undergo maintenance from

    8:00

    pm to 6:00 am daily. Which of the following can specify parameters for the maintenance work? (Select TWO).

    A. Managed security service
    B. Memorandum of understanding
    C. Quality of service
    D. Network service provider
    E. Operating level agreement

  • Question 439:

    A large organization has recently suffered a massive credit card breach. During the months of Incident Response, there were multiple attempts to assign blame for whose fault it was that the incident occurred. In which part of the incident response phase would this be addressed in a controlled and productive manner?

    A. During the Identification Phase
    B. During the Lessons Learned phase
    C. During the Containment Phase
    D. During the Preparation Phase

  • Question 440:

    A security administrator was informed that a server unexpectedly rebooted. The administrator received an export of syslog entries for analysis:

    Which of the following does the log sample indicate? (Choose two.)

    A. A root user performed an injection attack via kernel module
    B. Encrypted payroll data was successfully decrypted by the attacker
    C. Jsmith successfully used a privilege escalation attack
    D. Payroll data was exfiltrated to an attacker-controlled host
    E. Buffer overflow in memory paging caused a kernel panic
    F. Syslog entries were lost due to the host being rebooted

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.