Pass CAS-003 Brain Dump Updated Certification Sample Questions [Q184-Q200]

Share

Pass CAS-003 Brain Dump Updated Certification Sample Questions

Online CAS-003 Test Brain Dump Question and Test Engine

NEW QUESTION 184
The finance department has started to use a new payment system that requires strict PII security restrictions on various network devices. The company decides to enforce the restrictions and configure all devices appropriately. Which of the following risk response strategies is being used?

  • A. Mitigate
  • B. Accept
  • C. Transfer
  • D. Avoid

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 185
A PaaS provider deployed a new product using a DevOps methodology Because DevOps is used to support both development and production assets inherent separation of duties is limited To ensure compliance with security frameworks that require a specific set of controls relating to separation of duties the organization must design and implement an appropriate compensating control Which of the following would be MOST suitable in this scenario?

  • A. Configuration of increased levels of logging, monitoring and alerting on production access
  • B. Development of standard code libraries and usage of the WS-security module on all web servers
  • C. Configuration of MFA and context-based login restrictions for all DevOps personnel
  • D. Implementation of peer review, static code analysis and web application penetration testing against the staging environment

Answer: A

 

NEW QUESTION 186
A security administrator has noticed that an increased number of employees' workstations are becoming infected with malware. The company deploys an enterprise antivirus system as well as a web content filter, which blocks access to malicious web sites where malware files can be downloaded. Additionally, the company implements technical measures to disable external storage. Which of the following is a technical control that the security administrator should implement next to reduce malware infection?

  • A. Enforce mandatory security awareness training for all employees and contractors.
  • B. Block cloud-based storage software on the company network.
  • C. Deploy a network access control system with a persistent agent.
  • D. Implement an Acceptable Use Policy which addresses malware downloads.

Answer: B

Explanation:
The question states that the company implements technical measures to disable external storage. This is storage such as USB flash drives and will help to ensure that the users to do not bring unauthorized data that could potentially contain malware into the network.
We should extend this by blocking cloud-based storage software on the company network. This would block access to cloud-based storage services such as Dropbox or OneDrive.
Incorrect Answers:
A: An Acceptable Use Policy is always a good idea. However, it just tells the users how they 'should' use the company systems. It is not a technical control to prevent malware.
B: A network access control system is used to control access to the network. It does not prevent malware on client computers.
C: Mandatory security awareness training for all employees and contractors is always a good idea. However, it just educates the users about potential security risks. It is not a technical control to prevent malware.

 

NEW QUESTION 187
Two competing companies experienced similar attacks on their networks from various threat actors. To improve response times, the companies wish to share some threat intelligence about the sources and methods of attack. Which of the following business documents would be BEST to document this engagement?

  • A. Business partnership agreement
  • B. Memorandum of understanding
  • C. Interconnection security agreement
  • D. Service-level agreement

Answer: C

Explanation:
Section: (none)
Explanation/Reference:
Reference: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-47.pdf

 

NEW QUESTION 188
A new piece of ransomware got installed on a company's backup server which encrypted the hard drives containing the OS and backup application configuration but did not affect the deduplication data hard drives. During the incident response, the company finds that all backup tapes for this server are also corrupt. Which of the following is the PRIMARY concern?

  • A. Preventing the ransomware from re-infecting the server upon restore
  • B. Determining how to install HIPS across all server platforms to prevent future incidents
  • C. Validating the integrity of the deduplicated data
  • D. Restoring the data will be difficult without the application configuration

Answer: D

Explanation:
Ransomware is a type of malware that restricts access to a computer system that it infects in some way, and demands that the user pay a ransom to the operators of the malware to remove the restriction.
Since the backup application configuration is not accessible, it will require more effort to recover the data.
Eradication and Recovery is the fourth step of the incident response. It occurs before preventing future problems.
Incorrect Answers:
A: Preventing future problems is part of the Lessons Learned step, which is the last step in the incident response process.
B: Preventing future problems is part of the Lessons Learned step, which is the last step in the incident response process.
C: Since the incident did not affect the deduplicated data, it is not included in the incident response process.
References:
https://en.wikipedia.org/wiki/Ransomware
Gregg, Michael, and Billy Haines, CASP CompTIA Advanced Security Practitioner Study Guide, John Wiley & Sons, Indianapolis, 2012, p. 249

 

NEW QUESTION 189
A bank is initiating the process of acquiring another smaller bank. Before negotiations happen between the organizations, which of the follwing business documents would be used as the FIRST step in the process?

  • A. OLA
  • B. MOU
  • C. BPA
  • D. NDA

Answer: D

 

NEW QUESTION 190
Users have been reporting unusual automated phone calls, including names and phone numbers, that appear to come from devices internal to the company. Which of the following should the systems administrator do to BEST address this problem?

  • A. Change the settings on the phone system to use SIP-TLS.
  • B. Enable QoS configuration on the phone VLAN.
  • C. Add an ACL to the firewall to block VoIP.
  • D. Have the phones download new configurations over TFTP.

Answer: A

 

NEW QUESTION 191
Which of the following attacks can be mitigated by proper data retention policies?

  • A. Spear phishing
  • B. Watering hole
  • C. Man-in-the browser
  • D. Dumpster diving

Answer: D

 

NEW QUESTION 192
A security engineer is assessing a new IoT product. The product interfaces with the ODBII port of a vehicle and uses a Bluetooth connection to relay data to an onboard data logger located in the vehicle. The data logger can only transfer data over a custom USB cable. The engineer suspects a relay attack is possible against the cryptographic implementation used to secure messages between segments of the system. Which of the following tools should the engineer use to confirm the analysis?

  • A. Log analysis and reduction tools
  • B. Binary decompiler
  • C. Network-based fuzzer
  • D. Wireless protocol analyzer

Answer: D

 

NEW QUESTION 193
A hospital's security team recently determined its network was breached and patient data was accessed by an external entity. The Chief Information Security Officer (CISO) of the hospital approaches the executive management team with this information, reports the vulnerability that led to the breach has already been remediated, and explains the team is continuing to follow the appropriate incident response plan. The executive team is concerned about the hospital's brand reputation and asks the CISO when the incident should be disclosed to the affected patients. Which of the following is the MOST appropriate response?

  • A. Upon the approval of the Chief Executive Officer (CEO) to release information to the public
  • B. When all steps related to the incident response plan are completed
  • C. As soon as the public relations department is ready to be interviewed
  • D. When it is mandated by their legal and regulatory requirements
  • E. As soon as possible in the interest of the patients

Answer: D

 

NEW QUESTION 194
A security analyst has been assigned incident response duties and must instigate the response on a Windows device that appears to be compromised. Which of the following commands should be executed on the client FIRST?
A)

B)

C)

D)

  • A. Option A
  • B. Option B
  • C. Option D
  • D. Option C

Answer: A

 

NEW QUESTION 195
An organization is currently working with a client to migrate data between a legacy ERP system and a cloud- based ERP tool using a global PaaS provider. As part of the engagement, the organization is performing data deduplication and sanitization of client data to ensure compliance with regulatory requirements. Which of the following is the MOST likely reason for the need to sanitize the client data?

  • A. Data aggregation
  • B. Data isolation
  • C. Data sovereignty
  • D. Data analytics
  • E. Data volume

Answer: C

 

NEW QUESTION 196
An organization is concerned with potential data loss in the event of a disaster, and created a backup datacenter as a mitigation strategy. The current storage method is a single NAS used by all servers in both datacenters. Which of the following options increases data availability in the event of a datacenter failure?

  • A. Establish a SAN that replicates between datacenters.
  • B. Ensure each server has two HBAs connected through two routes to the NAS.
  • C. Replicate NAS changes to the tape backups at the other datacenter.
  • D. Establish deduplication across diverse storage paths.

Answer: A

Explanation:
A SAN is a Storage Area Network. It is an alternative to NAS storage. SAN replication is a technology that replicates the data on one SAN to another SAN; in this case, it would replicate the data to a SAN in the backup datacenter. In the event of a disaster, the SAN in the backup datacenter would contain all the data on the original SAN. Array-based replication is an approach to data backup in which compatible storage arrays use built-in software to automatically copy data from one storage array to another. Array- based replication software runs on one or more storage controllers resident in disk storage systems, synchronously or asynchronously replicating data between similar storage array models at the logical unit number (LUN) or volume block level.
The term can refer to the creation of local copies of data within the same array as the source data, as well as the creation of remote copies in an array situated off site.

 

NEW QUESTION 197
Which of the following is the MOST likely reason an organization would decide to use a BYOD policy?

  • A. It is the least complex method for systems administrator to maintain over time.
  • B. It should reduce the number of help desk and tickets significantly.
  • C. It enables employees to use the devices they are already own, thus reducing costs.
  • D. It is most secure, as the company owns and completely controls the devices.

Answer: C

 

NEW QUESTION 198
An organization is improving its web services to enable better customer engagement and self- service. The organization has a native mobile application and a rewards portal provided by a third party. The business wants to provide customers with the ability to log in once and have SSO between each of the applications. The integrity of the identity is important so it can be propagated through to back-end systems to maintain a consistent audit trail. Which of the following authentication and authorization types BEST meet the requirements? (Choose two.)

  • A. OpenID connect
  • B. Social login
  • C. SAML
  • D. SPML
  • E. OAuth
  • F. XACML

Answer: A,C

Explanation:
SAML or OpenID Connect - OAuth is authentication only, used for delegated access.

 

NEW QUESTION 199
A systems administrator establishes a CIFS share on a UNIX device to share data to Windows systems. The security authentication on the Windows domain is set to the highest level. Windows users are stating that they cannot authenticate to the UNIX share. Which of the following settings on the UNIX server would correct this problem?

  • A. Refuse LM and only accept NTLMv2
  • B. Accept only LM
  • C. Refuse NTLMv2 and accept LM
  • D. Accept only NTLM

Answer: A

Explanation:
In a Windows network, NT LAN Manager (NTLM) is a suite of Microsoft security protocols that provides authentication, integrity, and confidentiality to users. NTLM is the successor to the authentication protocol in Microsoft LAN Manager (LANMAN or LM), an older Microsoft product, and attempts to provide backwards compatibility with LANMAN. NTLM version 2 (NTLMv2), which was introduced in Windows NT 4.0 SP4 (and natively supported in Windows 2000), enhances NTLM security by hardening the protocol against many spoofing attacks, and adding the ability for a server to authenticate to the client.
This question states that the security authentication on the Windows domain is set to the highest level. This will be NTLMv2. Therefore, the answer to the question is to allow NTLMv2 which will enable the Windows users to connect to the UNIX server. To improve security, we should disable the old and insecure LM protocol as it is not used by the Windows computers.
Incorrect Answers:
B: The question states that the security authentication on the Windows domain is set to the highest level. This will be NTLMv2, not LM.
C: The question states that the security authentication on the Windows domain is set to the highest level. This will be NTLMv2, not LM so we need to allow NTLMv2.
D: The question states that the security authentication on the Windows domain is set to the highest level. This will be NTLMv2, not NTLM (version1).
References:
https://en.wikipedia.org/wiki/NT_LAN_Manager

 

NEW QUESTION 200
......

Real CompTIA CAS-003 Exam Dumps with Correct 574 Questions and Answers: https://www.prepawayexam.com/CompTIA/braindumps.CAS-003.ete.file.html

CompTIA CAS-003 Certification Real 2022 Mock Exam: https://drive.google.com/open?id=1n6wXW48Q_P4meE96FUOohZ_Ut3g2hpIh