Download CompTIA Advanced Security Practitioner (CASP).test-king.CAS-003.2019-04-25.1e.111q.vcex

Download Exam

File Info

Exam CompTIA Advanced Security Practitioner (CASP)
Number CAS-003
File Name CompTIA Advanced Security Practitioner (CASP).test-king.CAS-003.2019-04-25.1e.111q.vcex
Size 1.1 Mb
Posted April 25, 2019
Downloads 59

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.


With discount: 20%


Demo Questions

Question 1
An infrastructure team is at the end of a procurement process and has selected a vendor. As part of the final negotiations, there are a number of outstanding issues, including:
Indemnity clauses have identified the maximum liability 
The data will be hosted and managed outside of the company’s geographical location 
The number of users accessing the system will be small, and no sensitive data will be hosted in the solution. As the security consultant on the project, which of the following should the project’s security consultant recommend as the NEXT step?

  • A: Develop a security exemption, as it does not meet the security policies
  • B: Mitigate the risk by asking the vendor to accept the in-country privacy principles
  • C: Require the solution owner to accept the identified risks and consequences
  • D: Review the entire procurement process to determine the lessons learned

Question 2
A security administrator is hardening a TrustedSolaris server that processes sensitive data. The data owner has established the following security requirements:
The data is for internal consumption only and shall not be distributed to outside individuals 
The systems administrator should not have access to the data processed by the server 
The integrity of the kernel image is maintained 
Which of the following host-based security controls BEST enforce the data owner’s requirements? (Choose three.)

  • A: SELinux
  • B: DLP
  • C: HIDS
  • D: Host-based firewall
  • E: Measured boot
  • F: Data encryption
  • G: Watermarking

Question 3
An SQL database is no longer accessible online due to a recent security breach. An investigation reveals that unauthorized access to the database was possible due to an SQL injection vulnerability. To prevent this type of breach in the future, which of the following security controls should be put in place before bringing the database back online? (Choose two.)

  • A: Secure storage policies
  • B: Browser security updates
  • C: Input validation
  • D: Web application firewall
  • E: Secure coding standards
  • F: Database activity monitoring

Question 4
Given the following output from a local PC:


Which of the following ACLs on a stateful host-based firewall would allow the PC to serve an intranet website? 

  • A: Allow -> ANY
  • B: Allow ->
  • C: Allow ->
  • D: Allow ->

Question 5
A systems security engineer is assisting an organization’s market survey team in reviewing requirements for an upcoming acquisition of mobile devices. The engineer expresses concerns to the survey team about a particular class of devices that uses a separate SoC for baseband radio I/O. For which of the following reasons is the engineer concerned?

  • A: These devices can communicate over networks older than HSPA+ and LTE standards, exposing device communications to poor encryptions routines
  • B: The organization will be unable to restrict the use of NFC, electromagnetic induction, and Bluetooth technologies
  • C: The associated firmware is more likely to remain out of date and potentially vulnerable
  • D: The manufacturers of the baseband radios are unable to enforce mandatory access controls within their driver set

Question 6
During a security assessment, an organization is advised of inadequate control over network segmentation. The assessor explains that the organization’s reliance on VLANs to segment traffic is insufficient to provide segmentation based on regulatory standards. 
Which of the following should the organization consider implementing along with VLANs to provide a greater level of segmentation?

  • A: Air gaps
  • B: Access control lists
  • C: Spanning tree protocol
  • D: Network virtualization
  • E: Elastic load balancing

Question 7
To prepare for an upcoming audit, the Chief Information Security Officer (CISO) asks for all 1200 vulnerabilities on production servers to be remediated. The security engineer must determine which vulnerabilities represent real threats that can be exploited so resources can be prioritized to migrate the most dangerous risks. The CISO wants the security engineer to act in the same manner as would an external threat, while using vulnerability scan results to prioritize any actions. Which of the following approaches is described?

  • A: Blue team
  • B: Red team
  • C: Black box
  • D: White team

Question 8
An engineer is evaluating the control profile to assign to a system containing PII, financial, and proprietary data. 


Based on the data classification table above, which of the following BEST describes the overall classification?

  • A: High confidentiality, high availability
  • B: High confidentiality, medium availability
  • C: Low availability, low confidentiality
  • D: High integrity, low availability

Question 9
A security incident responder discovers an attacker has gained access to a network and has overwritten key system files with backdoor software. The server was reimaged and patched offline. Which of the following tools should be implemented to detect similar attacks?

  • A: Vulnerability scanner
  • B: TPM
  • C: Host-based firewall
  • D: File integrity monitor
  • E: NIPS

Question 10
An organization is in the process of integrating its operational technology and information technology areas. As part of the integration, some of the cultural aspects it would like to see include more efficient use of resources during change windows, better protection of critical infrastructure, and the ability to respond to incidents. The following observations have been identified:
The ICS supplier has specified that any software installed will result in lack of support. 
There is no documented trust boundary defined between the SCADA and corporate networks. 
Operational technology staff have to manage the SCADA equipment via the engineering workstation. 
There is a lack of understanding of what is within the SCADA network. 
Which of the following capabilities would BEST improve the security position?

  • A: VNC, router, and HIPS
  • B: SIEM, VPN, and firewall
  • C: Proxy, VPN, and WAF
  • D: IDS, NAC, and log monitoring



You can buy ProfExam with a 20% discount..

Get Now!


Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen


Use VCE Exam Simulator to open VCE files