CASP Recertification Real Exam Questions and Answers FREE CAS-003 Updated on Jan 06, 2022 [Q26-Q42]

Share

CASP Recertification CAS-003 Real Exam Questions and Answers FREE Updated on Jan 06, 2022

CAS-003 Ultimate Study Guide -  UpdateDumps


How to book the CAS-003 Exam

These are following steps for registering the CAS-003 exam. Step 1: Visit to CompTIA website Step 2: Purchase the CAS-003 exam Voucher Step 3: Login for the test Step 4: Find and select the testing location Step 5: Select Date, time and Schedule your test

 

NEW QUESTION 26
A Chief Security Officer (CSO) is reviewing the organization's incident response report from a recent incident. The details of the event indicate:
1. A user received a phishing email that appeared to be a report from the organization's CRM tool.
2. The user attempted to access the CRM tool via a fraudulent web page but was unable to access the tool.
3. The user, unaware of the compromised account, did not report the incident and continued to use the CRM tool with the original credentials.
4. Several weeks later, the user reported anomalous activity within the CRM tool.
5. Following an investigation, it was determined the account was compromised and an attacker in another country has gained access to the CRM tool.
6. Following identification of corrupted data and successful recovery from the incident, a lessons learned activity was to be led by the CSO.
Which of the following would MOST likely have allowed the user to more quickly identify the unauthorized use of credentials by the attacker?

  • A. WAYF-based authentication
  • B. Time-of-use controls
  • C. Security awareness training
  • D. Time-of-check controls
  • E. Last login verification
  • F. Log correlation

Answer: E

 

NEW QUESTION 27
A government contracting company issues smartphones to employees to enable access to corporate resources. Several employees will need to travel to a foreign country for business purposes and will require access to their phones. However, the company recently received intelligence that its intellectual property is highly desired by the same country's government. Which of the following MDM configurations would BEST reduce the risk of compromise while on foreign soil?

  • A. Disable firmware OTA updates.
  • B. Disable push notification services.
  • C. Disable location services.
  • D. Disable wipe

Answer: C

 

NEW QUESTION 28
A new security policy slates all wireless and wired authentication must include the use of certificates when connecting to internal resources within the enterprise LAN by all employees Which of the following should be configured to comply with the new security policy? (Select TWO).

  • A. OAuth
  • B. New pre-shared key
  • C. PKI
  • D. 8021X
  • E. Push-based authentication
  • F. SSO

Answer: C,D

 

NEW QUESTION 29
After the install process, a software application executed an online activation process. After a few months, the system experienced a hardware failure. A backup image of the system was restored on a newer revision of the same brand and model device. After the restore, the specialized application no longer works. Which of the following is the MOST likely cause of the problem?

  • A. The application is unable to perform remote attestation due to blocked ports.
  • B. The binary files used by the application have been modified by malware.
  • C. The hash key summary of hardware and installed software no longer match.
  • D. The restored image backup was encrypted with the wrong key.

Answer: C

Explanation:
Explanation
Different software vendors have different methods of identifying a computer used to activate software.
However, a common component used in software activations is a hardware key (or hardware and software key). This key is a hash value generated based on the hardware (and possibly software) installed on the system.
For example, when Microsoft software is activated on a computer, the software generates an installation ID that consists of the software product key used during the installation and a hardware key (hash value generated from the computer's hardware). The installation ID is submitted to Microsoft for software activation.
Changing the hardware on a system can change the hash key which makes the software think it is installed on another computer and is therefore not activated for use on that computer. This is most likely what has happened in this question.

 

NEW QUESTION 30
A small retail company recently deployed a new point of sale (POS) system to all 67 stores. The core of the POS is an extranet site, accessible only from retail stores and the corporate office over a split-tunnel VPN. An additional split-tunnel VPN provides bi-directional connectivity back to the main office, which provides voice connectivity for store VoIP phones. Each store offers guest wireless functionality, as well as employee wireless. Only the staff wireless network has access to the POS VPN. Recently, stores are reporting poor response times when accessing the POS application from store computers as well as degraded voice quality when making phone calls. Upon investigation, it is determined that three store PCs are hosting malware, which is generating excessive network traffic. After malware removal, the information security department is asked to review the configuration and suggest changes to prevent this from happening again. Which of the following denotes the BEST way to mitigate future malware risk?

  • A. Deploy a proxy server with content filtering at the corporate office and route all traffic through it.
  • B. Deploy new perimeter firewalls at all stores with UTM functionality.
  • C. Move to a VDI solution that runs offsite from the same data center that hosts the new POS solution.
  • D. Change antivirus vendors at the store and the corporate office.

Answer: B

Explanation:
A perimeter firewall is located between the local network and the Internet where it can screen network traffic flowing in and out of the organization. A firewall with unified threat management (UTM) functionalities includes anti-malware capabilities.
Incorrect Answers:
B: Antivirus applications prevent viruses, worms and Trojans but not other types of malware, such as spyware.
C: A virtual desktop infrastructure (VDI) solution refers to computer virtualization. It uses servers to provide desktop operating systems to a host machines. This reduces on-site support and improves centralized management. It does not mitigate against malware attacks.
D: Content filtering is used to control the types of email messages that flow in and out of an organization, and the types of web pages a user may access. It does not mitigate against malware attacks.
References:
Gregg, Michael, and Billy Haines, CASP CompTIA Advanced Security Practitioner Study Guide, John Wiley & Sons, Indianapolis, 2012, pp. 92, 124-127, 135-138

 

NEW QUESTION 31
The code snippet below controls all electronic door locks to a secure facility in which the doors should only fail open in an emergency. In the code, "criticalValue" indicates if an emergency is underway:

Which of the following is the BEST course of action for a security analyst to recommend to the software developer?

  • A. Add additional exception handling logic to the main program to prevent doors from being opened
  • B. Rewrite the software to implement fine-grained, conditions-based testing
  • C. Apply for a life-safety-based risk exception allowing secure doors to fail open
  • D. Rewrite the software's exception handling routine to fail in a secure state

Answer: A

 

NEW QUESTION 32
A company is acquiring incident response and forensic assistance from a managed security service provider in the event of a data breach. The company has selected a partner and must now provide required documents to be reviewed and evaluated. Which of the following documents would BEST protect the company and ensure timely assistance? (Choose two.)

  • A. RFI
  • B. NDA
  • C. MSA
  • D. RFQ
  • E. RA
  • F. BIA

Answer: B,C

 

NEW QUESTION 33
A security appliance vendor is reviewing an RFP that is requesting solutions for the defense of a set of web-based applications. This RFP is from a financial institution with very strict performance requirements. The vendor would like to respond with its solutions.
Before responding, which of the following factors is MOST likely to have an adverse effect on the vendor's qualifications?

  • A. The RFP is issued by a financial institution that is headquartered outside of the vendor's own country.
  • B. The solution employs threat information-sharing capabilities using a proprietary data model.
  • C. The overall solution proposed by the vendor comes in less that the TCO parameter in the RFP.
  • D. The vendor's proposed solution operates below the KPPs indicated in the RFP.

Answer: D

 

NEW QUESTION 34
The finance department has started to use a new payment system that requires strict PII security restrictions on various network devices. The company decides to enforce the restrictions and configure all devices appropriately. Which of the following risk response strategies is being used?

  • A. Transfer
  • B. Accept
  • C. Avoid
  • D. Mitigate

Answer: D

 

NEW QUESTION 35
A security engineer is responsible for monitoring company applications for known vulnerabilities. Which of the following is a way to stay current on exploits and information security news?

  • A. Subscribe to security mailing lists
  • B. Implement security awareness training
  • C. Ensure that the organization vulnerability management plan is up-to-date
  • D. Update company policies and procedures

Answer: A

Explanation:
Explanation
Subscribing to bug and vulnerability, security mailing lists is a good way of staying abreast and keeping up to date with the latest in those fields.

 

NEW QUESTION 36
A security analyst sees some suspicious entries in a log file from a web server website, which has a form that allows customers to leave feedback on the company's products. The analyst believes a malicious actor is scanning the web form. To know which security controls to put in place, the analyst first needs to determine the type of activity occurring to design a control. Given the log below:

Which of the following is the MOST likely type of activity occurring?

  • A. Brute forcing
  • B. XSS scanning
  • C. Fuzzing
  • D. SQLinjection

Answer: D

 

NEW QUESTION 37
During the migration of a company's human resources application to a PaaS provider, the Chief Privacy Officer (CPO) expresses concern the vendor's staff may be able to access data within the migrating applications. The application stack includes a multitier architecture and uses commercially available, vendor-supported software packages. Which of the following BEST addresses the CPO's concerns?

  • A. Ensure the platform vendor implement date-at-rest encryption on its storage.
  • B. Impalement a CASB that tokenizes company data in transit to the migrated applications.
  • C. Enable MFA to the vendor's tier of the architecture.
  • D. Execute non-disclosure agreements and background checks on vendor staff.

Answer: D

 

NEW QUESTION 38
A company has noticed recently that its corporate information has ended up on an online forum. An investigation has identified that internal employees are sharing confidential corporate information on a daily basis. Which of the following are the MOST effective security controls that can be implemented to stop the above problem? (Select TWO).

  • A. Implement a URL filter to block the online forum
  • B. Implement DLP on the desktop, email gateway, and web proxies
  • C. Security awareness compliance training for all employees
  • D. Review of security policies and procedures
  • E. Implement NIDS on the desktop and DMZ networks

Answer: B,C

Explanation:
Security awareness compliance training for all employees should be implemented to educate employees about corporate policies and procedures for working with information technology (IT). Data loss prevention (DLP) should be implemented to make sure that users do not send sensitive or critical information outside the corporate network.
Incorrect Answers:
A: A URL filter will prevent users from accessing the online forum, but it will not prevent them from sharing confidential corporate information.
B: NIDS will monitor traffic to and from all devices on the network, perform an analysis of passing traffic on the entire subnet, and matches the traffic that is passed on the subnets to the library of known attacks. It will not prevent access to the online forum, or from sharing confidential corporate information.
E: The problem is that users are not adhering to the security policies and procedures, so reviewing them will not solve the problem.
References:
http://searchsecurity.techtarget.com/definition/security-awareness-training
http://whatis.techtarget.com/definition/data-loss-prevention-DLP
https://en.wikipedia.org/wiki/Intrusion_detection_system

 

NEW QUESTION 39
Company.org has requested a black-box security assessment be performed on key cyber terrain. On area of concern is the company's SMTP services. The security assessor wants to run reconnaissance before taking any additional action and wishes to determine which SMTP server is Internet-facing.
Which of the following commands should the assessor use to determine this information?

  • A. dnsrecon -d company.org -t SOA
  • B. dig company.org mx
  • C. whois company.org
  • D. nc -v company.org

Answer: A

 

NEW QUESTION 40
After being notified of an issue with the online shopping cart, where customers are able to arbitrarily change the price of listed items, a programmer analyzes the following piece of code used by a web based shopping cart.
SELECT ITEM FROM CART WHERE ITEM=ADDSLASHES($USERINPUT);
The programmer found that every time a user adds an item to the cart, a temporary file is created on the web server /tmp directory. The temporary file has a name which is generated by concatenating the content of the $USERINPUT variable and a timestamp in the form of MM-DD- YYYY, (e.g. smartphone-12-25-2013.tmp) containing the price of the item being purchased.
Which of the following is MOST likely being exploited to manipulate the price of a shopping cart's items?

  • A. Input validation
  • B. TOCTOU
  • C. Session hijacking
  • D. SQL injection

Answer: D

 

NEW QUESTION 41
A company is in the process of outsourcing its customer relationship management system to a cloud provider. It will host the entire organization's customer database. The database will be accessed by both the company's users and its customers. The procurement department has asked what security activities must be performed for the deal to proceed. Which of the following are the MOST appropriate security activities to be performed as part of due diligence? (Select TWO).

  • A. Physical penetration test of the datacenter to ensure there are appropriate controls.
  • B. Review of the organizations security policies, procedures and relevant hosting certifications.
  • C. Security clauses are implemented into the contract such as the right to audit.
  • D. Penetration testing of the solution to ensure that the customer data is well protected.
  • E. Code review of the solution to ensure that there are no back doors located in the software.

Answer: B,C

Explanation:
Due diligence refers to an investigation of a business or person prior to signing a contract. Due diligence verifies information supplied by vendors with regards to processes, financials, experience, and performance. Due diligence should verify the data supplied in the RFP and concentrate on the following:
Company profile, strategy, mission, and reputation Financial status, including reviews of audited financial statements Customer references, preferably from companies that have outsourced similar processes Management qualifications, including criminal background checks Process expertise, methodology, and effectiveness Quality initiatives and certifications Technology, infrastructure stability, and applications Security and audit controls Legal and regulatory compliance, including any outstanding complaints or litigation Use of subcontractors Insurance Disaster recovery and business continuity policies C and D form part of Security and audit controls.

 

NEW QUESTION 42
......

Ultimate Guide to Prepare CAS-003 Certification Exam for CASP Recertification: https://www.updatedumps.com/CompTIA/CAS-003-updated-exam-dumps.html

Use Real CAS-003 Dumps - CompTIA Correct Answers: https://drive.google.com/open?id=1RICUXzyHctblepbQ2AHQ2MEdoNY4FyUL