[Oct 09, 2022] Pass Your CAS-003 Dumps Free Latest CompTIA Practice Tests
Get Top-Rated CompTIA CAS-003 Exam Dumps Now
About Exam
CAS-003 exam consists of a maximum of 90 questions that need to be completed in 165 minutes. The questions are in multiple-choice and performance-based format. You have the option to choose between two languages — English and Japanese. There is no scaled score in this exam; you either pass or fail. CAS-003 will cost $452 for candidates from the USA.
After the successful completion of the test, the candidates will be granted the CASP+ certification that will be valuable for both the employee and the enterprise. This certificate has been approved by the United States Department of Defense and its holders are preferred by Dell and HP for their advanced security personnel.
NEW QUESTION 323
A security analyst, who is working in a Windows environment, has noticed a significant amount of IPv6 traffic originating from a client, even though IPv6 is not currently in use. The client is a stand-alone device, not connected to the AD that manages a series of SCADA devices used for manufacturing. Which of the following is the appropriate command to disable the client's IPv6 stack?
- A. Option B
- B. Option A
- C. Option D
- D. Option C
Answer: D
NEW QUESTION 324
An engineer wants to assess the OS security configurations on a company's servers. The engineer has downloaded some files to orchestrate configuration checks When the engineer opens a file in a text editor, the following excerpt appears:
Which of the following capabilities would a configuration compliance checker need to support to interpret this file?
- A. SCAP
- B. Swagger file
- C. WSDL
- D. Nessus
- E. Netcat
Answer: A
NEW QUESTION 325
A well-known retailer has experienced a massive credit card breach. The retailer had gone through an audit and had been presented with a potential problem on their network. Vendors were authenticating directly to the retailer's AD servers, and an improper firewall rule allowed pivoting from the AD server to the DMZ where credit card servers were kept. The firewall rule was needed for an internal application that was developed, which presents risk. The retailer determined that because the vendors were required to have site to site VPN's no other security action was taken.
To prove to the retailer the monetary value of this risk, which of the following type of calculations is needed?
- A. Qualitative Risk Analysis
- B. A cost/benefit analysis
- C. Residual Risk calculation
- D. Quantitative Risk Analysis
Answer: D
Explanation:
Explanation
Performing quantitative risk analysis focuses on assessing the probability of risk with a metric measurement which is usually a numerical value based on money or time.
NEW QUESTION 326
An administrator wishes to replace a legacy clinical software product as it has become a security risk. The legacy product generates $10,000 in revenue a month. The new software product has an initial cost of $180,000 and a yearly maintenance of $2,000 after the first year. However, it will generate $15,000 in revenue per month and be more secure. How many years until there is a return on investment for this new package?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
Return on investment = Net profit / Investment
where:
Profit for the first year is $60 000, second year = $ 120 000 ; third year = $ 180 000 ; and fourth year = $ 240 000 investment in first year = $ 180 000, by year 2 = $ 182 000; by year 3 = $ 184 000 ; and by year 4 = $ 186 000 Thus you will only get a return on the investment in 4 years' time.
References:
http://www.financeformulas.net/Return_on_Investment.html
NEW QUESTION 327
A security administrator wants to deploy a dedicated storage solution which is inexpensive, can natively integrate with AD, allows files to be selectively encrypted and is suitable for a small number of users at a satellite office. Which of the following would BEST meet the requirement?
- A. NAS
- B. Virtual storage
- C. SAN
- D. Virtual SAN
Answer: A
Explanation:
A NAS is an inexpensive storage solution suitable for small offices. Individual files can be encrypted by using the EFS (Encrypted File System) functionality provided by the NTFS file system.
NAS typically uses a common Ethernet network and can provide storage services to any authorized devices on that network.
Two primary NAS protocols are used in most environments. The choice of protocol depends largely on the type of computer or server connecting to the storage. Network File System (NFS) protocol usually used by servers to access storage in a NAS environment.
Common Internet File System (CIFS), also sometimes called Server Message Block (SMB), is usually used for desktops, especially those running Microsoft Windows.
Unlike DAS and SAN, NAS is a file-level storage technology. This means the NAS appliance maintains and controls the files, folder structures, permission, and attributes of the data it holds. A typical NAS deployment integrates the NAS appliance with a user database, such as Active Directory, so file permissions can be assigned based on established users and groups. With Active Directory integration, most Windows New Technology File System (NTFS) permissions can be set on the files contained on a NAS device.
NEW QUESTION 328
A security auditor suspects two employees of having devised a scheme to steal money from the company. While one employee submits purchase orders for personal items, the other employee approves these purchase orders. The auditor has contacted the human resources director with suggestions on how to detect such illegal activities. Which of the following should the human resource director implement to identify the employees involved in these activities and reduce the risk of this activity occurring in the future?
- A. Job rotation
- B. Least privilege
- C. Background checks
- D. Employee termination procedures
Answer: A
Explanation:
Job rotation can reduce fraud or misuse by preventing an individual from having too much control over an area.
NEW QUESTION 329
A financial services company wants to migrate its email services from on-premises servers to a cloud-based email solution. The Chief information Security Officer (CISO) must brief board of directors on the potential security concerns related to this migration. The board is concerned about the following.
* Transactions being required by unauthorized individual
* Complete discretion regarding client names, account numbers, and investment information.
* Malicious attacker using email to distribute malware and ransom ware.
* Exfiltration of sensitivity company information.
The cloud-based email solution will provide an6-malware, reputation-based scanning, signature-based scanning, and sandboxing. Which of the following is the BEST option to resolve the board's concerns for this email migration?
- A. Data loss prevention
- B. Application whitelisting
- C. Endpoint detection response
- D. SSL VPN
Answer: A
NEW QUESTION 330
A legacy web application, which is being used by a hospital, cannot be upgraded for 12 months. A new vulnerability is found in the legacy application, and the networking team is tasked with mitigation. Middleware for mitigation will cost $100,000 per year. Which of the following must be calculated to determine ROI?
(Choose two.)
- A. MTBF
- B. ALE
- C. RPO
- D. ARO
- E. RTO
Answer: B,D
NEW QUESTION 331
An IT manager is concerned about the cost of implementing a web filtering solution in an effort to mitigate the risks associated with malware and resulting data leakage. Given that the ARO is twice per year, the ALE resulting from a data leak is $25,000 and the ALE after implementing the web filter is $15,000. The web filtering solution will cost the organization
$10,000 per year. Which of the following values is the single loss expectancy of a data leakage event after implementing the web filtering solution?
- A. $0
- B. $15,000
- C. $12,500
- D. $10,000
- E. $7,500
Answer: E
Explanation:
The annualized loss expectancy (ALE) is the product of the annual rate of occurrence (ARO) and the single loss expectancy (SLE). It is mathematically expressed as: ALE = ARO x SLE Single Loss Expectancy (SLE) is mathematically expressed as: Asset value (AV) x Exposure Factor (EF) SLE = AV x EF - Thus the Single Loss Expectancy (SLE) = ALE/ARO = $15,000 / 2 = $
7,500
References:
http://www.financeformulas.net/Return_on_Investment.html
https://en.wikipedia.org/wiki/Risk_assessment
NEW QUESTION 332
A security architect is reviewing the code for a company's financial website. The architect suggests adding the following HTML element, along with a server-side function, to generate a random number on the page used to initiate a funds transfer:
<input type="hidden" name="token" value=generateRandomNumber()>
Which of the following attacks is the security architect attempting to prevent?
- A. XSRF
- B. XSS
- C. Clickjacking
- D. SQL injection
Answer: A
NEW QUESTION 333
Using SSL, an administrator wishes to secure public facing server farms in three subdomains:
dc1.east.company.com, dc2.central.company.com, and dc3.west.company.com. Which of the following is the number of wildcard SSL certificates that should be purchased?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
You would need three wildcard certificates:
*. east.company.com
*. central.company.com
*. west.company.com
The common domain in each of the domains is company.com. However, a wildcard covers only one level of subdomain. For example: *. company.com will cover "<anything>.company.com" but it won't cover "<anything>.<anything>.company.com". You can only have one wildcard in a domain. For example: *.company.com. You cannot have *.*.company.com. Only the leftmost wildcard (*) is counted.
NEW QUESTION 334
An organization is creating requirements for new laptops that will be issued to staff One of the company's key security objectives is to ensure the laptops nave hardware-enforced data-at-rest protection tied to permanent hardware identities. The laptops must also provide attestation for secure boot processes To meet these demands, which of the following BEST represent the features that should be included in the requirements set? (Select TWO.)
- A. TLS1.3
- B. TPM2.0e
- C. Shim and GRUB
- D. Opal support
- E. MicroSD token authenticator
- F. ARMv7 with TrustZone
Answer: B,C
NEW QUESTION 335
A security architect is designing a system to satisfy user demand for reduced transaction time, increased security and message integrity, and improved cryptographic security. The resultant system will be used in an environment with a broad user base where many asynchronous transactions occur every minute and must be publicly verifiable.
Which of the following solutions BEST meets all of the architect's objectives?
- A. An agreement with an entropy-as-a-service provider to increase the amount of randomness in generated keys.
- B. An internal key infrastructure that allows users to digitally sign transaction logs
- C. An open distributed transaction ledger that requires proof of work to append entries.
- D. A publicly verified hashing algorithm that allows revalidation of message integrity at a future date.
Answer: B
NEW QUESTION 336
After embracing a BYOD policy, a company is faced with new security challenges from unmanaged mobile devices and laptops. The company's IT department has seen a large number of the following incidents:
* Duplicate IP addresses
* Rogue network devices
* Infected systems probing the company's network
Which of the following should be implemented to remediate the above issues? (Choose two.)
- A. HIPS
- B. Route protection
- C. NIDS
- D. Port security
- E. NAC
Answer: B,E
NEW QUESTION 337
An organization wants to allow its employees to receive corporate email on their own smartphones. A security analyst is reviewing the following information contained within the file system of an employee's smartphone:
FamilyPix.jpg
Taxreturn.tax
paystub.pdf
employeesinfo.xls
SoccerSchedule.doc
RecruitmentPlan.xls
Based on the above findings, which of the following should the organization implement to prevent further exposure? (Choose two.)
- A. Rooting
- B. Containerization
- C. Jailbreaking
- D. Side loading
- E. VPN
- F. Geofencing
- G. Remote wiping
Answer: B,G
NEW QUESTION 338
A security administrator is concerned about employees connecting their personal devices to the company network. Doing so is against company policy. The network does not have a NAC solution. The company uses a GPO that disables the firewall on all company-owned devices while they are connected to the internal network Additionally, all company-owned devices implement a standard naming convention that uses the device's serial number. The security administrator wants to identify active personal devices and write a custom script to disconnect them from the network Which of the following should the script use to BEST accomplish this task?
- A. Switch and router ARP tables
- B. AD authentication logs
- C. DHCP logs
- D. RADIUS logs
- E. Recursive DNS logs
Answer: A
NEW QUESTION 339
Given the following code snippet:
Of which of the following is this snippet an example?
- A. Improper filed usage
- B. Buffer overflow
- C. Data execution prevention
- D. Input validation
- E. Failure to use standard libraries
Answer: A
NEW QUESTION 340
A project manager is working with system owners to develop maintenance windows for system pathing and upgrades in a cloud-based PaaS environment. Management has indicated one maintenance windows will be authorized per month, but clients have stated they require quarterly maintenance windows to meet their obligations. Which of the following documents should the project manager review?
- A. SRTM
- B. SOW
- C. MOU
- D. SLA
Answer: D
NEW QUESTION 341
An analyst is investigating behavior on a corporate-owned, corporate-managed mobile device with application whitelisting enabled, based on a name string. The employee to whom the device is assigned reports the approved email client is displaying warning messages that can launch browser windows and is adding unrecognized email addresses to the "compose" window.
Which of the following would provide the analyst the BEST chance of understanding and characterizing the malicious behavior?
- A. Perform static code analysis on the source code.
- B. Analyze the device firmware via the JTAG interface.
- C. Penetration test the mobile application.
- D. Reverse engineer the application binary.
- E. Change to a whitelist that uses cryptographic hashing.
Answer: E
NEW QUESTION 342
An organization has implemented an Agile development process for front end web application development. A new security architect has just joined the company and wants to integrate security activities into the SDLC.
Which of the following activities MUST be mandated to ensure code quality from a security perspective? (Select TWO).
- A. For each major iteration penetration testing is performed
- B. A security design is performed at the end of the requirements phase
- C. Security standards and training is performed as part of the project
- D. Security requirements are story boarded and make it into the build
- E. Static and dynamic analysis is run as part of integration
- F. Daily stand-up meetings are held to ensure security requirements are understood
Answer: A,E
Explanation:
SDLC stands for systems development life cycle. An agile project is completed in small sections called iterations. Each iteration is reviewed and critiqued by the project team. Insights gained from the critique of an iteration are used to determine what the next step should be in the project.
Each project iteration is typically scheduled to be completed within two weeks.
Static and dynamic security analysis should be performed throughout the project. Static program analysis is the analysis of computer software that is performed without actually executing programs (analysis performed on executing programs is known as dynamic analysis). In most cases the analysis is performed on some version of the source code, and in the other cases, some form of the object code.
For each major iteration penetration testing is performed. The output of a major iteration will be a functioning part of the application. This should be penetration tested to ensure security of the application.
NEW QUESTION 343
An enterprise with global sites processes and exchanges highly sensitive information that is protected under several countries' arms trafficking laws. There is new information that malicious nation-state-sponsored activities are targeting the use of encryption between the geographically disparate sites. The organization currently employs ECDSA and ECDH with P-384, SHA-384, and AES-256-GCM on VPNs between sites.
Which of the following techniques would MOST likely improve the resilience of the enterprise to attack on cryptographic implementation?
- A. Add a second-layer VPN from a different vendor between sites.
- B. Use a stronger elliptic curve cryptography algorithm.
- C. Ensure cryptography modules are kept up to date from vendor supplying them.
- D. Upgrade the cipher suite to use an authenticated AES mode of operation.
- E. Implement an IDS with sensors inside (clear-text) and outside (cipher-text) of each tunnel between sites.
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 344
An internal staff member logs into an ERP platform and clicks on a record. The browser URL changes to:
URL: http://192.168.0.100/ERP/accountId=5&action=SELECT
Which of the following is the MOST likely vulnerability in this ERP platform?
- A. Plain-text credentials transmitted over the Internet
- B. Brute forcing of account credentials
- C. SQL injection of ERP back end
- D. Insecure direct object reference
Answer: D
NEW QUESTION 345
A developer is writing a new mobile application that employees will use to connect to an Internet-facing sensitive system The security team is concerned with MITM attacks against the encrypted application traffic aimed at intercepting and decrypting sensitive information from the server to the mobile client. Which of the following should the developer implement to address the security team's concerns? (Select TWO).
- A. OCSP
- B. Key stretching
- C. HSTS
- D. TLB 18
- E. Certificate pinning
Answer: D,E
NEW QUESTION 346
......
Passing Key To Getting CAS-003 Certified Exam Engine PDF: https://troytec.getvalidtest.com/CAS-003-brain-dumps.html