DUMPS BASE EXAM DUMPS COMPTIA CAS-003 28% OFF Automatically For You CompTIA Advanced Security Practitioner (CASP) Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification 1.A new database application was added to a company’s hosted VM environment. Firewall ACLs were modified to allow database users to access the server remotely. The company’s cloud security broker then identified abnormal from a database user on-site. Upon further investigation, the security team noticed the user ran code on a VM that provided access to the hypervisor directly and access to other sensitive data. Which of the following should the security do to help mitigate future attacks within the VM environment? (Choose two.) A. Install the appropriate patches. B. Install perimeter NGFW. C. Configure VM isolation. D. Deprovision database VM. E. Change the user’s access privileges. F. Update virus definitions on all endpoints. Answer: C,E 2. A developer needs to provide feedback on a peer’s work during the SDLC. While reviewing the code changes, the developers session ID tokens for a web application will be transmitted over an unsecure connection . Which of the following code snippets should the developer recommend implement to correct the vulnerability? A) B) C) D) Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification A. Option A B. Option B C. Option C D. Option D Answer: A 3. Ann, a terminated employee, left personal photos on a company-issued laptop and no longer has access to them. Ann emails her previous manager and asks to get her personal photos back . Which of the following BEST describes how the manager should respond? A. Determine if the data still exists by inspecting to ascertain if the laptop has already been wiped and if the storage team has recent backups. B. Inform Ann that the laptop was for company data only and she should not have stored personal photos on a company asset. C. Report the email because it may have been a spoofed request coming from an attacker who is trying to exfiltrate data from the company laptop. D. Consult with the legal and/or human resources department and check company policies around employment and termination procedures. Answer: D 4. A penetration test is being scoped for a set of web services with API endpoints. The APIs will be hosted on existing web application servers. Some of the new APIs will be available to unauthenticated users, but some will only be available to authenticated users . Which of the following tools or activities would the penetration tester MOST likely use or do during the engagement? (Select TWO.) A. Static code analyzer B. Intercepting proxy C. Port scanner D. Reverse engineering E. Reconnaissance gathering F. User acceptance testing Answer: B,E 5. A systems administrator receives an advisory email that a recently discovered exploit is being used in another country and the financial institutions have ceased Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification operations while they find a way to respond to the attack . Which of the following BEST describes where the administrator should look to find information on the attack to determine if a response must be prepared for the systems? (Choose two.) A. Bug bounty websites B. Hacker forums C. Antivirus vendor websites D. Trade industry association websites E. CVE database F. Company’s legal department Answer: B,D 6. Which of the following is the GREATEST security concern with respect to BYOD? A. The filtering of sensitive data out of data flows at geographic boundaries. B. Removing potential bottlenecks in data transmission paths. C. The transfer of corporate data onto mobile corporate devices. D. The migration of data into and out of the network in an uncontrolled manner. Answer: D 7. A security incident responder discovers an attacker has gained access to a network and has overwritten key system files with backdoor software. The server was reimaged and patched offline. Which of the following tools should be implemented to detect similar attacks? A. Vulnerability scanner B. TPM C. Host-based firewall D. File integrity monitor E. NIPS Answer: D 8. A system administrator recently conducted a vulnerability scan of the internet. Subsequently, the organization was successfully attacked by an adversary . Which of the following in the MOST likely explanation for why the organization network was compromised? A. There was a false positive since the network was fully patched. B. The system administrator did not perform a full system sun. C. The systems administrator performed a credentialed scan. D. The vulnerability database was not updated. Answer: C Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification 9. A network printer needs Internet access to function. Corporate policy states all devices allowed on the network must be authenticated . Which of the following is the MOST secure method to allow the printer on the network without violating policy? A. Request an exception to the corporate policy from the risk management committee B. Require anyone trying to use the printer to enter their username and password C. Have a help desk employee sign in to the printer every morning D. Issue a certificate to the printer and use certificate-based authentication Answer: D 10. Several days after deploying an MDM for smartphone control, an organization began noticing anomalous behavior across the enterprise Security analysts observed the following: • Unauthorized certificate issuance • Access to mutually authenticated resources utilizing valid but unauthorized certificates • Granted access to internal resources via the SSL VPN To address the immediate problem security analysts revoked the erroneous certificates . Which of the following describes the MOST likely root cause of the problem and offers a solution? A. The VPN and web resources are configured with too weak a cipher suite and should be rekeyed to support AES 256 in GCM and ECC for digital signatures and key exchange B. A managed mobile device is rooted, exposing its keystore and the MDM should be reconfigured to wipe these devices and disallow access to corporate resources C. SCEP is configured insecurely which should be enabled for device onboarding against a PKI for mobile-exclusive use D. The CA is configured to sign any received CSR from mobile users and should be reconfigured to permit CSR signings only from domain administrators. Answer: B 11. A Chief Information Security Officer (CISO) has created a survey that will be distributed to managers of mission-critical functions across the organization. The survey requires the managers to determine how long their respective units can operate in the event of an extended IT outage before the organization suffers monetary losses from the outage To which of the following is the survey question related? (Select TWO) A. Risk avoidance B. Business impact Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification C. Risk assessment D. Recovery point objective E. Recovery time objective F. Mean time between failures Answer: B,D 12. A manufacturing company's security engineer is concerned a remote actor may be able to access the ICS that is used to monitor the factory lines. The security engineer recently proposed some techniques to reduce the attack surface of the ICS to the Chief Information Security Officer (CISO) . Which of the following would BEST track the reductions to show the CISO the engineer's plan is successful during each phase? A. Conducting tabletop exercises to evaluate system risk B. Contracting a third-party auditor after the project is finished C. Performing pre- and post-implementation penetration tests D. Running frequent vulnerability scans during the project Answer: A 13. A project manager is working with a team that is tasked to develop software applications in a structured environment and host them in a vendor’s cloud-based infrastructure. The organization will maintain responsibility for the software but will not manage the underlying server applications . Which of the following does the organization plan to leverage? A. SaaS B. PaaS C. IaaS D. Hybrid cloud E. Network virtualization Answer: B 14. During a security event investigation, a junior analyst fails to create an image of a server’s hard drive before removing the drive and sending it to the forensics analyst. Later, the evidence from the analysis is not usable in the prosecution of the attackers due to the uncertainty of tampering . Which of the following should the junior analyst have followed? A. Continuity of operations B. Chain of custody C. Order of volatility D. Data recovery Answer: C Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification Explanation: References: 15. A Chief Information Security Officer (CISO) needs to create a policy set that meets international standards for data privacy and sharing . Which of the following should the CISO read and understand before writing the policies? A. PCI DSS B. GDPR C. NIST D. ISO 31000 Answer: B 16. A security is testing a server finds the following in the output of a vulnerability scan: Which of the following will the security analyst most likely use NEXT to explore this further? A. Exploitation framework B. Reverse engineering tools C. Vulnerability scanner D. Visualization tool Answer: A 17. The Chief Information Security Officer (CISO) of a company that has highly sensitive corporate locations wants its security engineers to find a solution to growing concerns regarding mobile devices. The CISO mandates the following requirements: Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification • The devices must be owned by the company for legal purposes. • The device must be as fully functional as possible when off site. • Corporate email must be maintained separately from personal email • Employees must be able to install their own applications. Which of the following will BEST meet the CISO's mandate? (Select TWO). A. Disable the device's camera B. Allow only corporate resources in a container. C. Use an MDM to wipe the devices remotely D. Block all sideloading of applications on devices E. Use geofencmg on certain applications F. Deploy phones in a BYOD model Answer: B,E 18. Following a complete outage of the electronic medical record system for more than 18 hours, the hospital’s Chief Executive Officer (CEO) has requested that the Chief Information Security Officer (CISO) perform an investigation into the possibility of a disgruntled employee causing the outage maliciously. To begin the investigation, the CISO pulls all event logs and device configurations from the time of the outage. The CISO immediately notices the configuration of a top-of-rack switch from one day prior to the outage does not match the configuration that was in place at the time of the outage. However, none of the event logs show who changed the switch configuration, and seven people have the ability to change it. Because of this, the investigation is inconclusive. Which of the following processes should be implemented to ensure this information is available for future investigations? A. Asset inventory management B. Incident response plan C. Test and evaluation D. Configuration and change management Answer: D 19. A security administrator wants to implement two-factor authentication for network switches and routers. The solution should integrate with the company’s RADIUS server, which is used for authentication to the network infrastructure devices. The security administrator implements the following: ✑ An HOTP service is installed on the RADIUS server. ✑ . The RADIUS server is configured to require the HOTP service for authentication. The configuration is successfully tested using a software supplicant and enforced across all network devices. Network administrators report they are unable to log onto the network devices because they are not being prompted for the second factor. Which of the following should be implemented to BEST resolve the issue? Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification A. Replace the password requirement with the second factor. Network administrators will enter their username and then enter the token in place of their password in the password field. B. Configure the RADIUS server to accept the second factor appended to the password. Network administrators will enter a password followed by their token in the password field. C. Reconfigure network devices to prompt for username, password, and a token. Network administrators will enter their username and password, and then they will enter the token. D. Install a TOTP service on the RADIUS server in addition to the HOTP service. Use the HOTP on older devices that do not support two-factor authentication. Network administrators will use a web portal to log onto these devices. Answer: B 20. A new corporate policy requires that all employees have access to corporate resources on personal mobile devices. The information assurance manager is concerned about the potential for inadvertent and malicious data disclosure if a device is lost, while users are concerned about corporate overreach . Which of the following controls would address these concerns and should be reflected in the company's mobile device policy? A. Place corporate applications in a container B. Enable geolocation on all devices C. install remote wiping capabilities D. Ensure all company communications use a VPN Answer: A 21. A company’s security policy states any remote connections must be validated using two forms of network-based authentication. It also states local administrative accounts should not be used for any remote access. PKI currently is not configured within the network. RSA tokens have been provided to all employees, as well as a mobile application that can be used for 2FA authentication. A new NGFW has been installed within the network to provide security for external connections, and the company has decided to use it for VPN connections as well . Which of the following should be configured? (Choose two.) A. Certificate-based authentication B. TACACS+ C. 802.1X D. RADIUS E. LDAP F. Local user database Answer: D,E Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification 22. Staff members are reporting an unusual number of device thefts associated with time out of the office. Thefts increased soon after the company deployed a new social networking app . Which of the following should the Chief Information Security Officer (CISO) recommend implementing? A. Automatic location check-ins B. Geolocated presence privacy C. Integrity controls D. NAC checks to quarantine devices Answer: B 23. After a large organization has completed the acquisition of a smaller company, the smaller company must implement new host-based security controls to connect its employees’ devices to the network. Given that the network requires 802.1X EAP- PEAP to identify and authenticate devices, which of the following should the security administrator do to integrate the new employees’ devices into the network securely? A. Distribute a NAC client and use the client to push the company’s private key to all the new devices. B. Distribute the device connection policy and a unique public/private key pair to each new employee’s device. C. Install a self-signed SSL certificate on the company’s RADIUS server and distribute the certificate’s public key to all new client devices. D. Install an 802.1X supplicant on all new devices and let each device generate a self- signed certificate to use for network access. Answer: D 24. Following the most recent patch deployment, a security engineer receives reports that the ERP application is no longer accessible. The security engineer reviews the situation and determines a critical security patch that was applied to the ERP server is the cause. The patch is subsequently backed out. Which of the following security controls would be BEST to implement to mitigate the threat caused by the missing patch? A. Anti-malware B. Patch testing C. HIPS D. Vulnerability scanner Answer: B Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification 25. An information security officer reviews a report and notices a steady increase in outbound network traffic over the past ten months. There is no clear explanation for the increase. The security officer interviews several business units and discovers an unsanctioned cloud storage provider was used to share marketing materials with potential customers . Which of the following services would be BEST for the security officer to recommend to the company? A. NIDS B. HIPS C. CASB D. SFTP Answer: C 26. A security administrator is concerned about employees connecting their personal devices to the company network. Doing so is against company policy. The network does not have a NAC solution. The company uses a GPO that disables the firewall on all company-owned devices while they are connected to the internal network Additionally, all company-owned devices implement a standard naming convention that uses the device's serial number. The security administrator wants to identify active personal devices and write a custom script to disconnect them from the network. Which of the following should the script use to BEST accomplish this task? A. Recursive DNS logs B. DHCP logs C. AD authentication logs D. RADIUS logs E. Switch and router ARP tables Answer: E 27. A security architect has been assigned to a new digital transformation program. The objectives are to provide better capabilities to customers and reduce costs. The program has highlighted the following requirements: ✑ Long-lived sessions are required, as users do not log in very often. ✑ . The solution has multiple SPs, which include mobile and web applications. ✑ A centralized IdP is utilized for all customer digital channels. ✑ . The applications provide different functionality types such as forums and customer portals. ✑ . The user experience needs to be the same across both mobile and web-based applications. Which of the following would BEST improve security while meeting these requirements? Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification A. Social login to IdP, securely store the session cookies, and implement one-time passwords sent to the mobile device B. Create-based authentication to IdP, securely store access tokens, and implement secure push notifications. C. Username and password authentication to IdP, securely store refresh tokens, and implement context-aware authentication. D. Username and password authentication to SP, securely store Java web tokens, and implement SMS OTPs. Answer: A 28. A security administrator is confirming specific ports and IP addresses that are monitored by the IPS-IDS system as well as the firewall placement on the perimeter network between the company and a new business partner. Which of the following business documents defines the parameters the security administrator must confirm? A. BIA B. ISA C. NDA D. MOU Answer: A 29. A software company is releasing a new mobile application to a broad set of external customers. Because the software company is rapidly releasing new features, it has built in an over-the-air software update process that can automatically update the application at launch time . Which of the following security controls should be recommended by the company’s security architect to protect the integrity of the update process? (Choose two.) A. Validate cryptographic signatures applied to software updates B. Perform certificate pinning of the associated code signing key C. Require HTTPS connections for downloads of software updates D. Ensure there are multiple download mirrors for availability E. Enforce a click-through process with user opt-in for new features Answer: A,B 30. A project manager is working with a software development group to collect and evaluate user stories related to the organization’s internally designed CRM tool. After defining requirements, the project manager would like to validate the developer’s interpretation and understanding of the user’s request . Which of the following would BEST support this objective? A. Peer review Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification B. Design review C. Scrum D. User acceptance testing E. Unit testing Answer: C 31. A newly hired security analyst has joined an established SOC team. Not long after going through corporate orientation, a new attack method on web-based applications was publicly revealed. The security analyst immediately brings this new information to the team lead, but the team lead is not concerned about it. Which of the following is the MOST likely reason for the team lead’s position? A. The organization has accepted the risks associated with web-based threats. B. The attack type does not meet the organization’s threat model. C. Web-based applications are on isolated network segments. D. Corporate policy states that NIPS signatures must be updated every hour. Answer: A 32. The government is concerned with remote military missions being negatively being impacted by the use of technology that may fail to protect operational security. To remediate this concern, a number of solutions have been implemented, including the following: ✑ End-to-end encryption of all inbound and outbound communication, including personal email and chat sessions that allow soldiers to securely communicate with families. ✑ Layer 7 inspection and TCP/UDP port restriction, including firewall rules to only allow TCP port 80 and 443 and approved applications ✑ A host-based whitelist of approved websites and applications that only allow mission-related tools and sites ✑ . The use of satellite communication to include multiple proxy servers to scramble the source IP address Which of the following is of MOST concern in this scenario? A. Malicious actors intercepting inbound and outbound communication to determine the scope of the mission B. Family members posting geotagged images on social media that were received via email from soldiers C. The effect of communication latency that may negatively impact real-time communication with mission control D. The use of centrally managed military network and computers by soldiers when communicating with external parties Answer: B Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification 33. Following a merger, the number of remote sites for a company has doubled to 52. The company has decided to secure each remote site with an NGFW to provide web filtering, NIDS/NIPS, and network antivirus. The Chief Information Officer (CIO) has requested that the security engineer provide recommendations on sizing for the firewall with the requirements that it be easy to manage and provide capacity for growth. The tables below provide information on a subset of remote sites and the firewall options: Which of the following would be the BEST option to recommend to the CIO? A. Vendor C for small remote sites, and Vendor B for large sites. B. Vendor B for all remote sites C. Vendor C for all remote sites D. Vendor A for all remote sites E. Vendor D for all remote sites Answer: D 34. A legacy web application, which is being used by a hospital, cannot be upgraded for 12 months. A new vulnerability is found in the legacy application, and the networking team is tasked with mitigation. Middleware for mitigation will cost $100,000 per year . Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification Which of the following must be calculated to determine ROI? (Choose two.) A. ALE B. RTO C. MTBF D. ARO E. RPO Answer: A,D 35. A security analyst is comparing two virtual servers that were bum from the same image and patched at the same regular intervals Server A is used to host a public- facing website, and Server B runs accounting software inside the firewalled accounting network. The analyst runs the same command and obtains the following output from Server A and Server B. respectively: Which of the following will the analyst most likely use NEXT? A. Exploitation tools B. Hash cracking tools C. Malware analysis tools D. Log analysis tools Answer: A 36. An administrator wants to ensure hard drives cannot be removed from hosts and men installed into and read by unauthorized hosts. Which of the following techniques would BEST support this? A. Access control lists B. TACACS+ server for AAA C. File-level encryption D. TPM with sealed storage Answer: A Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification 37. A government entity is developing requirements for an RFP to acquire a biometric authentication system. When developing these requirements, which of the following considerations is MOST critical to the verification and validation of the SRTM? A. Local and national laws and regulations B. Secure software development requirements C. Environmental constraint requirements D. Testability of requirements Answer: A 38. The email administrator must reduce the number of phishing emails by utilizing more appropriate security controls. The following configurations already are in place • Keyword Mocking based on word lists • URL rewriting and protection • Stopping executable files from messages Which of the following is the BEST configuration change for the administrator to make? A. Configure more robust word lists for blocking suspicious emails B. Configure appropriate regular expression rules per suspicious email received C. Configure Bayesian filtering to block suspicious inbound email D. Configure the mail gateway to strip any attachments Answer: B 39. An organization wants to allow its employees to receive corporate email on their own smartphones. A security analyst is reviewing the following information contained within the file system of an employee’s smartphone: FamilyPix.jpg Taxreturn.tax paystub.pdf employeesinfo.xls SoccerSchedule.doc RecruitmentPlan.xls Based on the above findings, which of the following should the organization implement to prevent further exposure? (Select two). A. Remote wiping B. Side loading C. VPN Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification D. Containerization E. Rooting F. Geofencing G. Jailbreaking Answer: A,C 40. A security technician is incorporating the following requirements in an RFP for a new SIEM: ✑ New security notifications must be dynamically implemented by the SIEM engine ✑ . The SIEM must be able to identify traffic baseline anomalies ✑ Anonymous attack data from all customers must augment attack detection and risk scoring Based on the above requirements, which of the following should the SIEM support? (Choose two.) A. Autoscaling search capability B. Machine learning C. Multisensor deployment D. Big Data analytics E. Cloud-based management F. Centralized log aggregation Answer: B,D 41. CORRECT TEXT You are a security analyst tasked with interpreting an Nmap scan output from Company A's privileged network. The company's hardening guidelines indicate the following: • There should be one primary server or service per device. • Only default ports should be used. • Non-secure protocols should be disabled. INSTRUCTIONS Using the Nmap output, identify the devices on the network and their roles, and any open ports that should be closed. For each device found, add a device entry to the Devices Discovered list, with the following information: • The IP address of the device • The primary server or service of the device • The protocol(s) that should be disabled based on the hardening guidelines Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification Answer: Add device for 10.1.45.66 as below: Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification 42. The SOC has noticed an unusual volume of traffic coming from an open WiFi guest network that appears correlated with a broader network slowdown. The network team is unavailable to capture traffic but logs from network services are available • No users have authenticated recently through the guest network's captive portal • DDoS mitigation systems are not alerting • DNS resolver logs show some very long domain names Which of the following is the BEST step for a security analyst to take next? A. Block all outbound traffic from the guest network at the border firewall B. Verify the passphrase on the guest network has not been changed. C. Search antivirus logs for evidence of a compromised company device D. Review access pent fogs to identify potential zombie services Answer: A Updated CAS-003 Dumps Questions V17.02 For CompTIA CASP+ Certification 43. A SaaS-based email service provider often receives reports from legitimate customers that their IP netblocks are on blacklists and they cannot send email. The SaaS has confirmed that affected customers typically have IP addresses within broader network ranges and some abusive customers within the same IP ranges may have performed spam campaigns . Which of the following actions should the SaaS provider perform to minimize legitimate customer impact? A. Inform the customer that the service provider does not have any control over third- party blacklist entries. The customer should reach out to the blacklist operator directly B. Perform a takedown of any customer accounts that have entries on email blacklists because this is a strong indicator of hostile behavior C. Work with the legal department and threaten legal action against the blacklist operator if the netblocks are not removed because this is affecting legitimate traffic D. Establish relationship with a blacklist operators so broad entries can be replaced with more granular entries and incorrect entries can be quickly pruned Answer: D 44. The Chief Information Officer (CIO) wants to increase security and accessibility among the organization’s cloud SaaS applications. The applications are configured to use passwords, and two-factor authentication is not provided natively . Which of the following would BEST address the CIO’s concerns? A. Procure a password manager for the employees to use with the cloud applications. B. Create a VPN tunnel between the on-premises environment and the cloud providers. C. Deploy applications internally and migrate away from SaaS applications. D. Implement an IdP that supports SAML and time-based, one-time passwords. Answer: B 45. Which of the following system would be at the GREATEST risk of compromise if found to have an open vulnerability associated with perfect ... secrecy? A. Endpoints B. VPN concentrators C. Virtual hosts D. SIEM E. Layer 2 switches Answer: B 46. A security engineer is working to secure an organization’s VMs. While reviewing the workflow for creating VMs on demand, the engineer raises a concern about the integrity of the secure boot process of the VM guest.