[Nov 20, 2021] CAS-003 Exam Dumps 100% Same Q&A In Your Real Exam [Q209-Q224]

Share

[Nov 20, 2021] CAS-003 Exam Dumps 100% Same Q&A In Your Real Exam

CAS-003 Test Engine Dumps Training With 574 Questions

NEW QUESTION 209
A security engineer must establish a method to assess compliance with company security policies as they apply to the unique configuration of individual endpoints, as well as to the shared configuration policies of common devices.

Which of the following tools is the security engineer using to produce the above output?

  • A. SCAP scanner
  • B. Vulnerability scanner
  • C. Port scanner
  • D. SIEM

Answer: D

 

NEW QUESTION 210
During a recent incident, sensitive data was disclosed and subsequently destroyed through a properly secured, cloud-based storage platform. An incident response technician is working with management to develop an after action report that conveys critical metrics regarding the incident.
Which of the following would be MOST important to senior leadership to determine the impact of the breach?

  • A. The likely per-record cost of the breach to the organization
  • B. The amount of downtime required to restore the data
  • C. The legal or regulatory exposure that exists due to the breach
  • D. The number of records compromised

Answer: D

 

NEW QUESTION 211
An enterprise with global sites processes and exchanges highly sensitive information that is protected under several countries' arms trafficking laws. There is new information that malicious nation-state-sponsored activities are targeting the use of encryption between the geographically disparate sites. The organization currently employs ECDSA and ECDH with P-384, SHA-384, and AES-256-GCM on VPNs between sites.
Which of the following techniques would MOST likely improve the resilience of the enterprise to attack on cryptographic implementation?

  • A. Ensure cryptography modules are kept up to date from vendor supplying them.
  • B. Upgrade the cipher suite to use an authenticated AES mode of operation.
  • C. Add a second-layer VPN from a different vendor between sites.
  • D. Use a stronger elliptic curve cryptography algorithm.
  • E. Implement an IDS with sensors inside (clear-text) and outside (cipher-text) of each tunnel between sites.

Answer: D

Explanation:
Explanation/Reference:

 

NEW QUESTION 212
A security manager looked at various logs while investigating a recent security breach in the data center from an external source. Each log below was collected from various security devices compiled from a report through the company's security information and event management server.
Logs:
Log 1:
Feb 5 23:55:37.743: %SEC-6-IPACCESSLOGS: list 10 denied 10.2.5.81 3 packets Log 2:
HTTP://www.company.com/index.php?user=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa Log 3:
Security Error Alert
Event ID 50: The RDP protocol component X.224 detected an error in the protocol stream and has disconnected the client Log 4:
Encoder oe = new OracleEncoder ();
String query = "Select user_id FROM user_data WHERE user_name = ' "
+ oe.encode ( req.getParameter("userID") ) + " ' and user_password = ' "
+ oe.encode ( req.getParameter("pwd") ) +" ' ";
Vulnerabilities
Buffer overflow
SQL injection
ACL
XSS
Which of the following logs and vulnerabilities would MOST likely be related to the security breach? (Select TWO).

  • A. SQL injection
  • B. XSS
  • C. Log 1
  • D. Log 4
  • E. ACL
  • F. Log 3
  • G. Buffer overflow
  • H. Log 2

Answer: G,H

Explanation:
Log 2 indicates that the security breach originated from an external source. And the vulnerability that can be associated with this security breach is a buffer overflow that happened when the amount of data written into the buffer exceeded the limit of that particular buffer.
Incorrect Answers:
A: Log 1 is not indicative of a security breach from an outside source
C: Log 3 will not be displayed if the breach in security came from an outside source.
D: Log 4 does not indicate an outside source responsible for the security breach.
F: The access control lists are mainly used to configure firewall rules and is thus not related to the security breach.
G: XSS would be indicative of an application issue and not a security breach that originated from the outside.
H: A SQL Injection is a type of attack that makes use of a series of malicious SQL queries in an attempt to directly manipulates the SQL database. This is not necessarily a security breach that originated from the outside.
References:
Gregg, Michael, and Billy Haines, CASP CompTIA Advanced Security Practitioner Study Guide, John Wiley & Sons, Indianapolis, 2012, pp. 110-112, 151. 153, 162

 

NEW QUESTION 213
Engineers at a company believe a certain type of data should be protected from competitors, but the data owner insists the information is not sensitive. An information security engineer is implementing controls to secure the corporate SAN. The controls require dividing data into four groups: non-sensitive, sensitive but accessible, sensitive but export-controlled, and extremely sensitive.
Which of the following actions should the engineer take regarding the data?

  • A. Label the data as extremely sensitive.
  • B. Label the data as sensitive but export-controlled.
  • C. Label the data as sensitive but accessible.
  • D. Label the data as non-sensitive.

Answer: D

 

NEW QUESTION 214
The marketing department has developed a new marketing campaign involving significant social media outreach. The campaign includes allowing employees and customers to submit blog posts and pictures of their day-to-day experiences at the company. The information security manager has been asked to provide an informative letter to all participants regarding the security risks and how to avoid privacy and operational security issues.
Which of the following is the MOST important information to reference in the letter?

  • A. Company policies and employee NDAs
  • B. After-action reports from prior incidents.
  • C. Social engineering techniques
  • D. Data classification processes

Answer: A

 

NEW QUESTION 215
After the departure of a developer under unpleasant circumstances, the company is concerned about the security of the software to which the developer has access. Which of the following is the BEST way to ensure security of the code following the incident?

  • A. Hirean externalred temtoconductblackboxtesting
  • B. Performregressiontesting and search forsuspiciouscode
  • C. Conductapeerreviewand crossreferencetheSRTM
  • D. Performwhite-box testingon allimpacted finishedproducts

Answer: A

 

NEW QUESTION 216
Company policy requires that all unsupported operating systems be removed from the network. The security administrator is using a combination of network based tools to identify such systems for the purpose of disconnecting them from the network. Which of the following tools, or outputs from the tools in use, can be used to help the security administrator make an approximate determination of the operating system in use on the local company network? (Select THREE).

  • A. Password cracker
  • B. 443/tcp open http
  • C. Passive banner grabbing
  • D. 09:18:16.262743 IP (tos 0x0, ttl 64, id 9870, offset 0, flags [none], proto TCP (6), length 40)
    192.168.1.3.1051 > 10.46.3.7.80: Flags [none], cksum 0x1800 (correct), win 512, length 0
  • E. Nmap
  • F. http://www.company.org/documents_private/index.php?search=string#&topic=windows&tcp=packet%20capture&cookie=wokdjwalkjcnie61lkasdf2aliser4
  • G. dig host.company.com

Answer: C,D,E

Explanation:
Banner grabbing and operating system identification can also be defined as fingerprinting the TCP/IP stack. Banner grabbing is the process of opening a connection and reading the banner or response sent by the application.
The output displayed in option F includes information commonly examined to fingerprint the OS.
Nmap provides features that include host discovery, as well as service and operating system detection.
Incorrect Answers:
B: A password cracker is used to recover passwords from data that have been stored in or transmitted by a computer system.
C: This answer is invalid as port 443 is used for HTTPS, not HTTP.
D: This web address link will not identify unsupported operating systems for the purpose of disconnecting them from the network.
E: The dig (domain information groper) command is a network administration command-line tool for querying Domain Name System (DNS) name servers.
References:
https://en.wikipedia.org/wiki/Dig_(command)
https://en.wikipedia.org/wiki/Password_cracking
https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
http://luizfirmino.blogspot.co.za/2011/07/understand-banner-grabbing-using-os.html?view=classic
Gregg, Michael, and Billy Haines, CASP CompTIA Advanced Security Practitioner Study Guide, John Wiley & Sons, Indianapolis, 2012, pp. 174, 175

 

NEW QUESTION 217
A security architect is designing a new infrastructure using both type 1 and type 2 virtual machines. In addition to the normal complement of security controls (e.g. antivirus, host hardening, HIPS/NIDS) the security architect needs to implement a mechanism to securely store cryptographic keys used to sign code and code modules on the VMs.
Which of the following will meet this goal without requiring any hardware pass-through implementations?

  • A. INE
  • B. HSM
  • C. TPM
  • D. vTPM

Answer: D

Explanation:
A Trusted Platform Module (TPM) is a microchip designed to provide basic security-related functions, primarily involving encryption keys. The TPM is usually installed on the motherboard of a computer, and it communicates with the remainder of the system by using a hardware bus.
A vTPM is a virtual Trusted Platform Module.
IBM extended the current TPM V1.2 command set with virtual TPM management commands that allow us to create and delete instances of TPMs. Each created instance of a TPM holds an association with a virtual machine (VM) throughout its lifetime on the platform.

 

NEW QUESTION 218
The Chief Information Security Officer (CISO) has asked the security team to determine whether the organization is susceptible to a zero-day exploit utilized in the banking industry and whether attribution is possible. The CISO has asked what process would be utilized to gather the information, and then wants to apply signatureless controls to stop these kinds of attacks in the future. Which of the following are the MOST appropriate ordered steps to take to meet the CISO's request?

  • A. 1. Analyze the current threat intelligence2. Utilize information sharing to obtain the latest industry IOCs3. Perform a sweep across the network to identify positive matches4. Apply machine learning algorithms
  • B. 1. Apply artificial intelligence algorithms for detection2. Inform the CERT team3. Research threat intelligence and potential adversaries4. Utilize threat intelligence to apply Big Data techniques
  • C. 1. Obtain the latest IOCs from the open source repositories2. Perform a sweep across the network to identify positive matches3. Sandbox any suspicious files4. Notify the CERT team to apply a future proof threat model
  • D. 1. Perform the ongoing research of the best practices2. Determine current vulnerabilities and threats3.
    Apply Big Data techniques4. Use antivirus control

Answer: C

 

NEW QUESTION 219
A security administrator wants to allow external organizations to cryptographically validate the company's
domain name in email messages sent by employees. Which of the following should the security
administrator implement?

  • A. TLS
  • B. S/MIME
  • C. DKIM
  • D. SPF

Answer: C

Explanation:
Explanation/Reference:
Reference: https://en.wikipedia.org/wiki/DMARC

 

NEW QUESTION 220
A security engineer successfully exploits an application during a penetration test. As proof of the exploit, the security engineer takes screenshots of how data was compromised in the application. Given the information below from the screenshot.

Which of the following tools was MOST likely used to exploit the application?

  • A. The engineer used a cross-site script sent via curl to edit the data
  • B. The engineer queried the server and edited the data using an HTTP proxy interceptor
  • C. The engineer captured the data with a protocol analyzer, and then utilized Python to edit the data
  • D. The engineer captured the HTTP headers, and then replaced the JSON data with a banner-grabbing tool

Answer: B

 

NEW QUESTION 221
A development team releases updates to an application regularly. The application is compiled with several standard open-source security products that require a minimum version for compatibility. During the security review portion of the development cycle, which of the following should be done to minimize possible application vulnerabilities?

  • A. The application should eliminate the use of open-source libraries and products to prevent known vulnerabilities from being included.
  • B. The developers should require an exact version of the open-source security products, preventing the introduction of new vulnerabilities.
  • C. The change logs for the third-party libraries should be reviewed for security patches, which may need to be included in the release.
  • D. The application development team should move to an Agile development approach to identify security concerns faster

Answer: C

 

NEW QUESTION 222
A security engineer is responsible for monitoring company applications for known vulnerabilities.
Which of the following is a way to stay current on exploits and information security news?

  • A. Ensure that the organization vulnerability management plan is up-to-date
  • B. Subscribe to security mailing lists
  • C. Implement security awareness training
  • D. Update company policies and procedures

Answer: B

Explanation:
Subscribing to bug and vulnerability, security mailing lists is a good way of staying abreast and keeping up to date with the latest in those fields.

 

NEW QUESTION 223
An organization is reviewing endpoint security solutions. In evaluating products, the organization has the following requirements:
1. Support server, laptop, and desktop infrastructure
2. Due to limited security resources, implement active protection capabilities
3. Provide users with the ability to self-service classify information and apply policies
4. Protect data-at-rest and data-in-use
Which of the following endpoint capabilities would BEST meet the above requirements? (Select two.)

  • A. Rights management
  • B. Antivirus
  • C. Data loss prevention
  • D. Endpoint detect and respond
  • E. Application whitelisting
  • F. Log monitoring

Answer: A,D

 

NEW QUESTION 224
......


Career Opportunities

The CompTIA CASP+ certification is considered an industry-standard in risk management and enterprise security. Earning it will open up various career opportunities with decent annual salaries, that include:

  • Security Architect $122k
  • Application Security Engineer $98k
  • Technical Lead Analyst $92k
  • Security Engineer $92k

 

CAS-003 Practice Test Pdf Exam Material: https://www.actualtestsquiz.com/CAS-003-test-torrent.html

CAS-003 Questions Pass on Your First Attempt Dumps for CASP Recertification Certified: https://drive.google.com/open?id=1YMsBzbdjQsJkKn_GNyEoy7cXnw6N3BxK