Skip to main content

RC0-C02 Real Exam Questions

CompTIA Advanced Security Practitioner (CASP) Recertification Exam for Continuing Education

308 questions available · Page 1 of 31

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

A health service provider is considering the impact of allowing doctors and nurses access to the internal email system from their personal smartphones. The Information Security Officer (ISO) has received a technical document from the security administrator explaining that the current email system is capable of enforcing security policies to personal smartphones, including screen lockout and mandatory PINs.
Additionally, the system is able to remotely wipe a phone if reported lost or stolen.
Which of the following should the Information Security Officer be MOST concerned with based on this scenario?
(Select THREE).

  1. A

    The email system may become unavailable due to overload.

  2. B

    Compliance may not be supported by all smartphones.

  3. C

    Equipment loss, theft, and data leakage.

  4. D

    Smartphone radios can interfere with health equipment.

  5. E

    Data usage cost could significantly increase.

  6. F

    Not all smartphones natively support encryption.

  7. G

    Smartphones may be used as rogue access points.

Show answer and explanation

Correct answers: B, C, F

Question 2 Single choice

The Chief Executive Officer (CEO) of a small start-up company wants to set up offices around the country for the sales staff to generate business. The company needs an effective communication solution to remain in constant contact with each other, while maintaining a secure business environment. A junior-level administrator suggests that the company and the sales staff stay connected via free social media.

Which of the following decisions is BEST for the CEO to make?

  1. A

    Social media is an effective solution because it is easily adaptable to new situations.

  2. B

    Social media is an ineffective solution because the policy may not align with the business.

  3. C

    Social media is an effective solution because it implements SSL encryption.

  4. D

    Social media is an ineffective solution because it is not primarily intended for business applications.

Show answer and explanation

Correct answer: B

Explanation

Social media networks are designed to draw people's attention quickly and to connect people is thus the main focus; security is not the main concern. Thus the CEO should decide that it would be ineffective to
use social media in the company as it does not align with the company business.

Question 3 Single choice

An administrator wants to enable policy based flexible mandatory access controls on an open source OS to prevent abnormal application modifications or executions.

Which of the following would BEST accomplish this?

  1. A

    Access control lists

  2. B

    SELinux

  3. C

    IPtables firewall

  4. D

    HIPS

Show answer and explanation

Correct answer: B

Explanation

The most common open source operating system is LINUX. Security-Enhanced Linux (SELinux) was created by the United States National Security Agency (NSA) and is a Linux kernel security module that provides a mechanism for supporting access control security policies, including United States Department of Defensetyle mandatory access controls (MAC).
NSA Security-enhanced Linux is a set of patches to the Linux kernel and some utilities to incorporate a strong, flexible mandatory access control (MAC) architecture into the major subsystems of the kernel. It provides an enhanced mechanism to enforce the separation of information based on confidentiality and integrity requirements, which allows threats of tampering and bypassing of application security mechanisms to be addressed and enables the confinement of damage that can be caused by malicious or flawed applications.

Question 4 Single choice

Two universities are making their 802.11n wireless networks available to the other university's students.
The infrastructure will pass the student's credentials back to the home school for authentication via the Internet.

The requirements are:

Mutual authentication of clients and authentication server

The design should not limit connection speeds

Authentication must be delegated to the home school No passwords should be sent unencrypted

The following design was implemented:

WPA2 Enterprise using EAP-PEAP-MSCHAPv2 will be used for wireless security

RADIUS proxy servers will be used to forward authentication requests to the home school

The RADIUS servers will have certificates from a common public certificate authority

A strong shared secret will be used for RADIUS server authentication

Which of the following security considerations should be added to the design?

  1. A

    The transport layer between the RADIUS servers should be secured

  2. B

    WPA Enterprise should be used to decrease the network overhead

  3. C

    The RADIUS servers should have local accounts for the visiting students

  4. D

    Students should be given certificates to use for authentication to the network

Show answer and explanation

Correct answer: A

Explanation

One of the requirements in this question states, "No passwords should be sent unencrypted". The design that was implemented makes no provision for the encryption of passwords as they are sent between RADIUS servers. The local RADIUS servers will pass the student's credentials back to the home school RADIUS servers for authentication via the Internet. When passing sensitive data such as usernames and passwords over the internet, the data should be sent over a secure connection. We can secure the transport layer between the RADIUS servers by implementing TLS (Transport Layer Security).
Transport Layer Security (TLS) is a protocol that ensures privacy between communicating applications and their users on the Internet. When a server and client communicate, TLS ensures that no third party may eavesdrop or tamper with any message. TLS is the successor to the Secure Sockets Layer (SSL).

Question 5 Single choice

A recently hired security administrator is advising developers about the secure integration of a legacy in-house application with a new cloud based processing system. The systems must exchange large amounts of fixed format data such as names, addresses, and phone numbers, as well as occasional chunks of data in unpredictable formats. The developers want to construct a new data format and create custom tools to parse and process the data. The security administrator instead suggests that the developers:

  1. A

    Create a custom standard to define the data.

  2. B

    Use well formed standard compliant XML and strict schemas.

  3. C

    Only document the data format in the parsing application code.

  4. D

    Implement a de facto corporate standard for all analyzed data.

Show answer and explanation

Correct answer: B

Explanation

Explanation: To ensure the successful parsing of the data, the XML code containing the data should be well-formed. We can use strict schemas to ensure the correct formatting of the data.
XML has two main advantages: first, it offers a standard way of structuring data, and, second, we can specify the vocabulary the data uses. We can define the vocabulary (what elements and attributes an XML document can use) using either a document type definition (DTD) or the XML Schema language.
Schemas provide the ability to define an element's type (string, integer, etc.) and much finer constraints (a positive integer, a string starting with an uppercase letter, etc.). DTDs enforce a strict ordering of elements;
schemas have a more flexible range of options. Finally schemas are written in XML, whereas DTDs have their own syntax. For an application to accept an XML document, it must be both well formed and valid. A document that is not well formed is not really XML and doesn't conform to the W3C's stipulations for an XML document. A parser will fail when given that document, even if validation is turned off.

Question 6 Single choice

An IT manager is working with a project manager to implement a new ERP system capable of transacting data between the new ERP system and the legacy system. As part of this process, both parties must agree to the controls utilized to secure data connections between the two enterprise systems.
This is commonly documented in which of the following formal documents?

  1. A

    Memorandum of Understanding

  2. B

    Information System Security Agreement

  3. C

    Interconnection Security Agreement

  4. D

    Interoperability Agreement

  5. E

    Operating Level Agreement

Show answer and explanation

Correct answer: C

Explanation

An interconnection security agreement (ISA) is a security document that derails the requirements for establishing, maintaining, and operating an interconnection between systems or networks. It specifies the requirements for connecting the systems and networks and details what security controls are co be used to protect the systems and sensitive data.

Question 7 Single choice

A manager who was attending an all-day training session was overdue entering bonus and payroll information for subordinates. The manager felt the best way to get the changes entered while in training was to log into the payroll system, and then activate desktop sharing with a trusted subordinate. The manager granted the subordinate control of the desktop thereby giving the subordinate full access to the payroll system. The subordinate did not have authorization to be in the payroll system. Another employee reported the incident to the security team.

Which of the following would be the MOST appropriate method for dealing with this issue going forward?

  1. A

    Provide targeted security awareness training and impose termination for repeat violators.

  2. B

    Block desktop sharing and web conferencing applications and enable use only with approval.

  3. C

    Actively monitor the data traffic for each employee using desktop sharing or web conferencing applications.

  4. D

    Permanently block desktop sharing and web conferencing applications and do not allow its use at the company.

Show answer and explanation

Correct answer: A

Question 8 Single choice

A business unit of a large enterprise has outsourced the hosting and development of a new external website which will be accessed by premium customers, in order to speed up the time to market timeline.

Which of the following is the MOST appropriate?

  1. A

    The external party providing the hosting and website development should be obligated under contract to provide a secure service which is regularly tested (vulnerability and penetration). SLAs should be in place for the resolution of newly identified vulnerabilities and a guaranteed uptime.

  2. B

    The use of external organizations to provide hosting and web development services is not recommended as the costs are typically higher than what can be achieved internally. In addition, compliance with privacy regulations becomes more complex and guaranteed uptimes are difficult to track and measure.

  3. C

    Outsourcing transfers all the risk to the third party. An SLA should be in place for the resolution of newly identified vulnerabilities and penetration / vulnerability testing should be conducted regularly.

  4. D

    Outsourcing transfers the risk to the third party, thereby minimizing the cost and any legal obligations.
    An MOU should be in place for the resolution of newly identified vulnerabilities and penetration / vulnerability testing should be conducted regularly.

Show answer and explanation

Correct answer: A

Explanation

A service level agreement (SLA) guarantees the level of service the partner is agreeing to provide. It specifies the uptime, response time, and maximum outage time that the partner is agreeing to.

Question 9 Single choice

Which of the following BEST constitutes the basis for protecting VMs from attacks from other VMs hosted on the same physical platform?

  1. A

    Aggressive patch management on the host and guest OSs.

  2. B

    Host based IDS sensors on all guest OSs.

  3. C

    Different antivirus solutions between the host and guest OSs.

  4. D

    Unique Network Interface Card (NIC) assignment per guest OS.

Show answer and explanation

Correct answer: A

Explanation

This question is asking "Which of the following BEST constitutes the basis for protecting VMs from attacks from other VMs hosted on the same physical platform. In other words, what is the primary method protecting VMs.
The first thing we should do to protect the VMs is to ensure that the guest OS's are patched and ensure that the host is patched. The host provides the virtualization software to enable the running of the virtual machines. Any floors in the virtualization software that affect the VM separation enabling an attack between VMs running on the host would hopefully be fixed by the virtualization software vendor in a patch.
The most important step and therefore "the basis" for protecting VMs would be aggressive patch management.

Question 10 Single choice

As part of a new wireless implementation, the Chief Information Officer's (CIO's) main objective is to immediately deploy a system that supports the 802.11r standard, which will help wireless VoIP devices in moving vehicles. However, the 802.11r standard was not ratified by the IETF. The wireless vendor's products do support the pre-ratification version of 802.11r. The security and network administrators have
tested the product and do not see any security or compatibility issues; however, they are concerned that the standard is not yet final.

Which of the following is the BEST way to proceed?

  1. A

    Purchase the equipment now, but do not use 802.11r until the standard is ratified.

  2. B

    Do not purchase the equipment now as the client devices do not yet support 802.11r.

  3. C

    Purchase the equipment now, as long as it will be firmware upgradeable to the final 802.11r standard.

  4. D

    Do not purchase the equipment now; delay the implementation until the IETF has ratified the final
    802.11r standard.

Show answer and explanation

Correct answer: C