Pass4Leader CAS-003 Exam Questions Real CAS-003 Practice Dumps [Q91-Q106]

Share

Pass4Leader CAS-003 Exam Questions | Real CAS-003 Practice Dumps

Verified CAS-003 Exam Dumps Q&As - Provide CAS-003 with Correct Answers


Research, Development & Collaboration: 13%

  • Implementing security events across a technology lifecycle: the knowledge areas that will be measured within this topic include systems development lifecycle; asset management; software development lifecycle; adapting solutions to address.
  • Describing the importance of interactions across different business units in achieving security goals: this section covers one’s skills in providing impartial recommendations and objective guidance to senior management and staff on security controls and processes; establishing efficient collaboration in teams for implementing secure solutions; interpreting security prerequisites and objectives to interact with stakeholders from different disciplines.
  • Applying research techniques to establish industry trends and the impact on the enterprise: the individuals should have a good understanding of research security implications of budding business tools; threat intelligence; global IA community/industry; performing ongoing research.

All these topics are neatly organized into 5 domains:

  1. Risk management

    Under this domain, the candidates should be able to synthesize business and industry influences and understand the related security risks. This requires knowledge of risk management, business models, influencing factors, and more. The applicants also have to have an idea about security and privacy policies, the ability to contrast and compare them, and up-to-date knowledge on policy and process life cycle.

    In addition, an understanding of strategies for risk mitigation, security controls, reverse engineering of existing solutions, common business documents, and general privacy principles is needed. The candidates should be able to analyze risk metric scenarios and use that to provide security.

  2. Enterprise security architecture

    This domain will cover various security components, protocols, vulnerabilities, and more. The candidates ought to understand how to analyze a scenario and successfully integrate network and security concepts and architectures while meeting the presented requirements. The knowledge of various physical and virtual network and security devices, applications, and protocol, network designs, etc. is essential.

    The applicants should also be able to perform the integration of security controls for the host device while meeting the security requirements. This involves knowledge of trusted OS, security software, host hardening, hardware vulnerabilities. Furthermore, one should have the skills to successfully integrate security controls on mobile devices. Knowledge of enterprise mobility management, rooting, tokenization, etc. is vital for this.

    Finally, exam-takers need to be able to choose the appropriate security controls for given vulnerability scenarios. This requires knowledge of various application issues, application security designs, database activity monitoring, firmware vulnerabilities, and more.

  3. Enterprise security operations

    When solving the tasks related to this domain, the candidates are given a scenario where they should successfully conduct an evaluation using various security methods such as malware sandboxing, fingerprinting, pivoting, and such. Knowledge of different network tools is required for analyzing those scenarios and choosing an appropriate tool. Furthermore, the knowledge of e-discovery, data breach, and the various aspects related to that should be used by candidates to implement incident response and execute proper recovery procedures.

  4. Technical integration of enterprise security

    In the fourth domain, the applicants are given a scenario that will test their knowledge of the integration of networks, hosts, storage, and applications to secure enterprise architecture. This requires an understanding of diverse standards, adaption to data flow security, interoperability issues, data security considerations, network secure segmentation and delegation, and such. Moreover, the candidates should be able to integrate cloud and virtualization technologies into secure enterprise architecture using their knowledge of cloud augmented security services, data security, vulnerabilities, and more.

    This domain also tests the candidates' ability to integrate and troubleshoot advanced authentication and authorization technologies. This also involves understanding various aspects of attestation, identity proofing, and more. The candidates are required to have an idea about cryptographic techniques as well as the ability to expertly select suitable control to secure communications and collaboration solutions.

  5. Research, development, and collaboration

    To answer the questions under this section, the candidates should perform research whilst applying proper methods and determine industry trends to identify the impact on the enterprise. This requires knowledge of research practices, security implications of business tools, and such. Moreover, implementing security activities across the technology life cycle, which is included in this domain, will be benefited by one's knowledge of system development life cycle, software development life cycle, documentation, etc.

    Finally, individuals need to know and explain the importance of interaction across business units to achieve security goals. This includes knowledge of implementation of security requirements, and aspects related to it, among others.

 

NEW QUESTION 91
There have been some failures of the company's internal facing website. A security engineer has found the WAF to be the root cause of the failures. System logs show that the WAF has been unavailable for 14 hours over the past month, in four separate situations. One of these situations was a two hour scheduled maintenance time, aimed at improving the stability of the WAF. Using the MTTR based on the last month's performance figures, which of the following calculations is the percentage of uptime assuming there were 722 hours in the month?

  • A. 98.06 percent
  • B. 99.72 percent
  • C. 98.34 percent
  • D. 92.24 percent

Answer: A

Explanation:
A web application firewall (WAF) is an appliance, server plugin, or filter that applies a set of rules to an HTTP conversation. Generally, these rules cover common attacks such as cross-site scripting (XSS) and SQL injection. By customizing the rules to your application, many attacks can be identified and blocked.
14h of down time in a period of 772 supposed uptime = 14/772 x 100 = 1.939 % Thus the % of uptime = 100% - 1.939% = 98.06%

 

NEW QUESTION 92
Given the following code snippet:

Which of the following failure modes would the code exhibit?

  • A. Open
  • B. Exception
  • C. Secure
  • D. Halt

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 93
A security analyst is responsible for the completion of a vulnerability assessment at a regional healthcare facility The analyst reviews the following Nmap output:
nmap -v -p scription=SMB-check-value ---scription-ags=unsafe =1 192.168.1.0/24 Which of the following is MOST likely what the security analyst is reviewing?

  • A. An Nmap script to scan for vulnerable SMB servers
  • B. An Nmap script to scan (or unsafe servers on UOP 445
  • C. An Nmap script to stop the SMB servers
  • D. An Nmap script 10 run the SMB servers

Answer: B

 

NEW QUESTION 94
An organization, which handles large volumes of PII, allows mobile devices that can process, store, and transmit PII and other sensitive data to be issued to employees. Security assessors can demonstrate recovery and decryption of remnant sensitive data from device storage after MDM issues a successful wipe command. Assuming availability of the controls, which of the following would BEST protect against the loss of sensitive data in the future?

  • A. Useencryption keysfor sensitivedata stored in an eFuse-backedmemoryspacethatisblownduring remote wipe.
  • B. ImplementacontainerthatwrapsPIIdataand storeskeyingmaterial directlyinthecontainer's encrypted application space.
  • C. Issuedevicesthatemployastrongeralgorithm for theauthentication ofsensitivedata stored onthem.
  • D. Procuredevicesthatremovethe bootloaderbinaries uponreceiptof anMDM-issued remotewipe command.

Answer: B

 

NEW QUESTION 95
A company monitors the performance of all web servers using WMI. A network administrator informs the security engineer that web servers hosting the company's client-facing portal are running slowly today. After some investigation, the security engineer notices a large number of attempts at enumerating host information via SNMP from multiple IP addresses.
Which of the following would be the BEST technique for the security engineer to employ in an attempt to prevent reconnaissance activity?

  • A. Install a HIPS on the web servers
  • B. Disable SNMP on the web servers
  • C. Install anti-DDoS protection in the DMZ
  • D. Disable inbound traffic from offending sources

Answer: A

 

NEW QUESTION 96
An enterprise is trying to secure a specific web-based application by forcing the use of multifactor authentication.
Currently, the enterprise cannot change the application's sign-in page to include an extra field.
However, the web-based application supports SAML. Which of the following would BEST secure the application?

  • A. Enabling the web application to support LDAP integration
  • B. Deploying Shibboleth to all web-based applications in the enterprise
  • C. Using an SSO application that supports mutlifactor authentication
  • D. Forcing higher-complexity passwords and frequent changes

Answer: B

 

NEW QUESTION 97
An organization is preparing to develop a business continuity plan. The organization is required to meet regulatory requirements relating to confidentiality and availability, which are well-defined.
Management has expressed concern following initial meetings that the organization is not fully aware of the requirements associated with the regulations. Which of the following would be MOST appropriate for the project manager to solicit additional resources for during this phase of the project?

  • A. Gap assessment
  • B. Risk analysis
  • C. After-action reports
  • D. Business impact assessment
  • E. Security requirements traceability matrix

Answer: A

 

NEW QUESTION 98
A security consultant is attempting to discover if the company is utilizing databases on client machines to store the customer data. The consultant reviews the following information:

Which of the following commands would have provided this output?

  • A. netstat -a
  • B. sqlmap -w
  • C. arp -s
  • D. ifconfig -arp

Answer: A

 

NEW QUESTION 99
A server (10.0.0.2) on the corporate network is experiencing a DoS from a number of marketing desktops that have been compromised and are connected to a separate network segment. The security engineer implements the following configuration on the management router:

Which of the following is the engineer implementing?

  • A. Remotely triggered black hole
  • B. Route protection
  • C. Address space layout randomization
  • D. Transport security
  • E. Port security

Answer: B

 

NEW QUESTION 100
A security consultant is considering authentication options for a financial institution. The following authentication options are available. Drag and drop the security mechanism to the appropriate use case.
Options may be used once.

Answer:

Explanation:

 

NEW QUESTION 101
A company's existing forward proxies support software-based TLS decryption, but are currently at 60% load just dealing with AV scanning and content analysis for HTTP traffic. More than 70% outbound web traffic is currently encrypted. The switching and routing network infrastructure precludes adding capacity, preventing the installation of a dedicated TLS decryption system. The network firewall infrastructure is currently at 30% load and has software decryption modules that can be activated by purchasing additional license keys. An existing project is rolling out agent updates to end-user desktops as part of an endpoint security refresh.
Which of the following is the BEST way to address these issues and mitigate risks to the organization?

  • A. Purchase the SSL, decryption license for the firewalls and route traffic back to the proxies for end-user categorization and malware analysis.
  • B. Use an EDP solution to address the malware issue and accept the diminishing role of the proxy for URL categorization in the short team.
  • C. Accept the current risk and seek possible funding approval in the next budget cycle to replace the existing proxies with ones with more capacity.
  • D. Roll out application whitelisting to end-user desktops and decommission the existing proxies, freeing up network ports.

Answer: D

 

NEW QUESTION 102
A company is facing penalties for failing to effectively comply with e-discovery requests. Which of the following could reduce the overall risk to the company from this issue?

  • A. Establish a policy that only allows filesystem encryption and disallows the use of individual file encryption.
  • B. Permit users to only encrypt individual files using their domain password and archive all old user passwords.
  • C. Allow encryption only by tools that use public keys from the existing escrowed corporate PKI.
  • D. Require each user to log passwords used for file encryption to a decentralized repository.

Answer: C

Explanation:
Electronic discovery (also called e-discovery) refers to any process in which electronic data is sought, located, secured, and searched with the intent of using it as evidence in a civil or criminal legal case. E-discovery can be carried out offline on a particular computer or it can be done in a network.
An e-discovery policy would define how data is archived and encrypted. If the data is archived in an insecure manor, a user could be able to delete data that the user does not want to be searched. Therefore, we need to find a way of securing the data in a way that only authorized people can access the data.
A public key infrastructure (PKI) supports the distribution and identification of public encryption keys for the encryption of data. The data can only be decrypted by the private key.
In this question, we have an escrowed corporate PKI. Escrow is an independent and licensed third party that holds something (money, sensitive data etc.) and releases it only when predefined conditions have been met. In this case, Escrow is holding the private key of the PKI.
By encrypting the e-discovery data by using the PKI public key, we can ensure that the data can only be decrypted by the private key held in Escrow and this will only happen when the predefined conditions are met.

 

NEW QUESTION 103
The results of an external penetration test for a software development company show a small number of applications account for the largest number of findings. While analyzing the content and purpose of the applications, the following matrix is created.

The findings are then categorized according to the following chart:

Which of the following would BEST reduce the amount of immediate risk incurred by the organization from a compliance and legal standpoint? (Select TWO)

  • A. Place a WAF in line with Application 2
  • B. Move Application 3 to a secure VLAN and require employees to use a jump server for access.
  • C. Implement an IDS/IPS on the same network segment as Application 3
  • D. Apply the missing OS and software patches to the server hosting Application 4
  • E. Use network segmentation and ACLs to control access to Application 5.
  • F. Install a FIM on the server hosting Application 4

Answer: A,E

 

NEW QUESTION 104
A security engineer must establish a method to assess compliance with company security policies as they apply to the unique configuration of individual endpoints, as well as to the shared configuration policies of common devices.

Which of the following tools is the security engineer using to produce the above output?

  • A. Port scanner
  • B. Vulnerability scanner
  • C. SIEM
  • D. SCAP scanner

Answer: C

 

NEW QUESTION 105
A large company with a very complex IT environment is considering a move from an on-premises, internally managed proxy to a cloud-based proxy solution managed by an external vendor. The current proxy provides caching, content filtering, malware analysis, and URL categorization for all staff connected behind the proxy.
Staff members connect directly to the Internet outside of the corporate network. The cloud-based version of the solution would provide content filtering, TLS decryption, malware analysis, and URL categorization. After migrating to the cloud solution, all internal proxies would be decommissioned. Which of the following would MOST likely change the company's risk profile?

  • A. 1. The loss of local caching would dramatically increase ISP changes and impact existing bandwidth.2.
    There would be a greater likelihood of Internet access outages due to lower resilience of cloud gateways.3. There would be a loss of internal intellectual knowledge regarding proxy configurations and application data flows.
  • B. 1. The external vendor would have access to inbound and outbound gateway traffic.2. The service would provide some level of protection for staff working from home.3. Outages would be likely to occur for systems or applications with hard-coded proxy information.
  • C. 1. Outages would be likely to occur for systems or applications with hard-coded proxy information.2.
    The service would provide some level of protection for staff members working from home.3. Malware detection times would decrease due to third-party management of the service.
  • D. 1. There would be a loss of internal intellectual knowledge regarding proxy configurations and application data flows.2. There would be a greater likelihood of Internet access outages due to lower resilience of cloud gateways.3. There would be data sovereignty concerns due to changes required in routing and proxy PAC files.

Answer: C

 

NEW QUESTION 106
......


What are the main requirements for CompTIA CAS-003 exam?

The right candidates for the CAS-003 exam have advanced skills in cybersecurity and possess some working experience in the IT field. The requirements for the test include at least 10 years of IT experience in the area of administration. This includes 5 years of performing technical security tasks. An applicant should have a deep awareness of the exam topics as well.

 

Get Top-Rated CompTIA CAS-003 Exam Dumps Now: https://www.pass4leader.com/CompTIA/CAS-003-exam.html

Pass Your CAS-003 Dumps Free Latest CompTIA Practice Tests: https://drive.google.com/open?id=1SKbqMSWS5QoJ79_rc0oaNIUiCVdzjASc