CAS-003 Exam Details

  • Exam Code
    :CAS-003
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :791 Q&As
  • Last Updated
    :Jan 22, 2024

CompTIA CAS-003 Online Questions & Answers

  • Question 611:

    A security architect is designing a system to satisfy user demand for reduced transaction time, increased security and message integrity, and improved cryptographic security. The resultant system will be used in an environment with a broad user base where many asynchronous transactions occur every minute and must be publicly verifiable.

    Which of the following solutions BEST meets all of the architect's objectives?

    A. An internal key infrastructure that allows users to digitally sign transaction logs
    B. An agreement with an entropy-as-a-service provider to increase the amount of randomness in generated keys.
    C. A publicly verified hashing algorithm that allows revalidation of message integrity at a future date.
    D. An open distributed transaction ledger that requires proof of work to append entries.

  • Question 612:

    A security engineer discovers a PC may have been breached and accessed by an outside agent. The engineer wants to find out how this breach occurred before remediating the damage. Which of the following should the security engineer do FIRST to begin this investigation?

    A. Create an image of the hard drive
    B. Capture the incoming and outgoing network traffic
    C. Dump the contents of the RAM
    D. Parse the PC logs for information on the attacker.

  • Question 613:

    During a security event investigation, a junior analyst fails to create an image of a server's hard drive before removing the drive and sending it to the forensics analyst. Later, the evidence from the analysis is not usable in the prosecution of the attackers due to the uncertainty of tampering. Which of the following should the junior analyst have followed?

    A. Continuity of operations
    B. Chain of custody
    C. Order of volatility
    D. Data recovery

  • Question 614:

    A security engineer has been hired to design a device that will enable the exfiltration of data from within a well-defended network perimeter during an authorized test. The device must bypass all firewalls and NIDS in place, as well as allow for the upload of commands from a centralized command and control answer. The total cost of the device must be kept to a minimum in case the device is discovered during an assessment. Which of the following tools should the engineer load onto the device being designed?

    A. Custom firmware with rotating key generation
    B. Automatic MITM proxy
    C. TCP beacon broadcast software
    D. Reverse shell endpoint listener

  • Question 615:

    Following a recent and very large corporate merger, the number of log files an SOC needs to review has approximately tripled. The Chief Information Security Officer (CISO) has not been allowed to hire any more staff for the SOC, but is looking for other ways to automate the log review process so the SOC receives less noise. Which of the following would BEST reduce log noise for the SOC?

    A. SIEM filtering
    B. Machine learning
    C. Outsourcing
    D. Centralized IPS

  • Question 616:

    A security administrator is updating corporate policies to respond to an incident involving collusion between two systems administrators that went undetected for more than six months.

    Which of the following policies would have MOST likely uncovered the collusion sooner? (Choose two.)

    A. Mandatory vacation
    B. Separation of duties
    C. Continuous monitoring
    D. Incident response
    E. Time-of-day restrictions
    F. Job rotation

  • Question 617:

    An administrator wants to enable policy based flexible mandatory access controls on an open source OS to prevent abnormal application modifications or executions. Which of the following would BEST accomplish this?

    A. Access control lists
    B. SELinux
    C. IPtables firewall
    D. HIPS

  • Question 618:

    A pentester must attempt to crack passwords on a windows domain that enforces strong complex passwords. Which of the following would crack the MOST passwords in the shortest time period?

    A. Online password testing
    B. Rainbow tables attack
    C. Dictionary attack
    D. Brute force attack

  • Question 619:

    Within change management, winch of the following ensures functions are earned out by multiple employees?

    A. Least privilege
    B. Mandatory vacation
    C. Separator of duties
    D. Job rotation

  • Question 620:

    Given the following information about a company's internal network:

    User IP space: 192.168.1.0/24

    Server IP space: 192.168.192.0/25

    A security engineer has been told that there are rogue websites hosted outside of the proper server space, and those websites need to be identified. Which of the following should the engineer do?

    A. Use a protocol analyzer on 192.168.1.0/24
    B. Use a port scanner on 192.168.1.0/24
    C. Use an HTTP interceptor on 192.168.1.0/24
    D. Use a port scanner on 192.168.192.0/25
    E. Use a protocol analyzer on 192.168.192.0/25
    F. Use an HTTP interceptor on 192.168.192.0/25

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.