πŸ”

CAS-005 β€” questions

Page 10 of 20 Β· 393 total questions.

Topic 1 Β· Question 185 Β· Select all that apply

A security administrator is performing a gap assessment against a specific OS benchmark. The benchmark requires the following configurations be applied to endpoints: β€’ Full disk encryption β€’ Host-based firewall β€’ Time synchronization β€’ Password policies β€’ Application allow listing β€’ Zero Trust application access Which of the following solutions best addresses the requirements? (Choose two.)

  • AMDM (correct answer)
  • BCASB
  • CSBoM
  • DSCAP
  • ESASE (correct answer)
  • FHIDS
Reveal answer & explanation
Correct answer: A, E

The correct answer is A, E. Option A: MDM Option E: SASE This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 186

A security analyst is reviewing the following authentication logs: Which of the following should the analyst do first?

Exhibit 1 for question 186
  • ADisable User2’s account.
  • BDisable User12’s account
  • CDisable User8’s account
  • DDisable User1’s account (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Disable User1’s account This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 187

A game developer wants to reach new markets and is advised by legal counsel to include specific age-related sign-up requirements. Which of the following best describes the legal counsel's concerns?

  • AGDPR
  • BLGPD
  • CPCI DSS
  • DCOPPA (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: COPPA

Topic 1 Β· Question 188

During a recent audit, a company's systems were assessed Given the following information: Which of the following is the best way to reduce the attack surface?

Exhibit 1 for question 188
  • ADeploying an EDR solution to all impacted machines in manufacturing
  • BSegmenting the manufacturing network with a firewall and placing the rules in monitor mode
  • CSetting up an IDS inline to monitor and detect any threats to the software
  • DImplementing an application-aware firewall and writing strict rules for the application access (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Implementing an application-aware firewall and writing strict rules for the application access

Explanation

A firewall enforces traffic policy by permitting or blocking connections based on configured rules.

Topic 1 Β· Question 189

A global manufacturing company has an internal application that is critical to making products. This application cannot be updated and must be available in the production area. A security architect is implementing security for the application. Which of the following best describes the action the architect should take?

  • ADisallow wireless access to the application.
  • BDeploy intrusion detection capabilities using a network tap
  • CCreate an acceptable use policy for the use of the application
  • DCreate a separate network for users who need access to the application (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Create a separate network for users who need access to the application This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 190

A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should maintain 99.999% availability and authorized users should only be able to gain access to data they are explicitly authorized to view. Which of the following threat-modeling frameworks directly addresses the CISO’s concerns about this system?

  • ACAPEC
  • BSTRIDE (correct answer)
  • CATT&CK
  • DTAXII
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: STRIDE This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 191

A company's internal network is experiencing a security breach and the threat actor is still active Due to business requirements, users in this environment are allowed to utilize multiple machines at the same time. Given the following log snippet: Which of the following accounts should a security analyst disable to best contain the incident without impacting valid users?

Exhibit 1 for question 191
  • Auser-Π°
  • Buser-b
  • Cuser-с
  • Duser-d (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: user-d This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 192

A security team is responding to malicious activity and needs to determine the scope of impact. The malicious activity appears to affect a certain version of an application used by the organization. Which of the following actions best enables the team to determine the scope of impact?

  • APerforming a port scan
  • BInspecting egress network traffic
  • CReviewing the asset inventory (correct answer)
  • DAnalyzing user behavior
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Reviewing the asset inventory This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 193

An organization recently implemented a policy that requires all passwords to be rotated every 90 days. An administrator sees a large volume of failed sign-on logs from multiple servers that are often accessed by users. The administrator determines users are disconnecting from the RDP session but not logging off. Which of the following should the administrator do to prevent account lockouts?

  • AIncrease the account lockout threshold
  • BEnforce password complexity
  • CAutomate logout of inactive sessions (correct answer)
  • DExtend the allowed session length
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Automate logout of inactive sessions

Topic 1 Β· Question 194

A security review revealed that not all of the client proxy traffic is being captured. Which of the following architectural changes best enables the capture of traffic for analysis?

  • AAdding an additional proxy server to each segmented VLAN (correct answer)
  • BSetting up a reverse proxy for client logging at the gateway
  • CConfiguring a span port on the perimeter firewall to ingest logs
  • DEnabling client device logging and system event auditing
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Adding an additional proxy server to each segmented VLAN

Explanation

A VLAN creates a logical layer-2 broadcast domain to segment devices independently of physical location. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 195 Β· Select all that apply

A security architect is onboarding a new EDR agent on servers that traditionally do not have internet access. In order for the agent to receive updates and report back to the management console, some changes must be made. Which of the following should the architect do to best accomplish this requirement? (Choose two.)

  • ACreate a firewall rule to only allow traffic from the subnet to the internet via a proxy. (correct answer)
  • BConfigure a proxy policy that blocks all traffic on port 443
  • CConfigure a proxy policy that allows only fully qualified domain names needed to communicate to a portal (correct answer)
  • DCreate a firewall rule to only allow traffic from the subnet to the internet via port 443.
  • ECreate a firewall rule to only allow traffic from the subnet to the internet to fully qualified names that are not identified as malicious by the firewall vendor
  • FConfigure a proxy policy that blocks only lists of known-bad fully qualified domain names
Reveal answer & explanation
Correct answer: A, C

The correct answer is A, C. Option A: Create a firewall rule to only allow traffic from the subnet to the internet via a proxy. Option C: Configure a proxy policy that allows only fully qualified domain names needed to communicate to a portal

Explanation

A firewall enforces traffic policy by permitting or blocking connections based on configured rules. Subnetting divides an IP network into smaller routing and broadcast domains for address efficiency and segmentation. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 196

Due to an infrastructure optimization plan, a company has moved from a unified architecture to a federated architecture divided by region. Long-term employees now have a better experience, but new employees are experiencing major performance issues when traveling between regions. The company is reviewing the following information: Which of the following is the most effective action to remediate the issue?

Exhibit 1 for question 196
  • ACreating a new user entry in the affected region for the affected employee
  • BSynchronizing all regions' user identities and ensuring ongoing synchronization (correct answer)
  • CRestarting European region physical access control systems
  • DResyncing single sign-on application with connected security appliances
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Synchronizing all regions' user identities and ensuring ongoing synchronization

Topic 1 Β· Question 197

A company hosts a platform-as-a-service solution with a web-based front end, through which customers interact with data sets. A security administrator needs to deploy controls to prevent application-focused attacks. Which of the following most directly supports the administrator’s objective?

  • AImproving security dashboard visualization on SIEM
  • BRotating API access and authorization keys every two months
  • CImplementing application load balancing and cross-region availability
  • DCreating WAF policies for relevant programming languages (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Creating WAF policies for relevant programming languages This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 198

A security officer received several complaints from users about excessive MFA push notifications at night. The security team investigates and suspects malicious activities regarding user account authentication. Which of the following is the best way for the security officer to restrict MFA notifications?

  • AProvisioning FIDO2 devices (correct answer)
  • BDeploying a text message based on MFA
  • CEnabling OTP via email
  • DConfiguring prompt-driven MFA
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Provisioning FIDO2 devices This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 199

A security analyst is troubleshooting the reason a specific user is having difficulty accessing company resources. The analyst reviews the following information: Which of the following is most likely the cause of the issue?

Exhibit 1 for question 199
  • AThe local network access has been configured to bypass MFA requirements.
  • BA network geolocation is being misidentified by the authentication server. (correct answer)
  • CAdministrator access from an alternate location is blocked by company policy.
  • DSeveral users have not configured their mobile devices to receive OTP codes.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: A network geolocation is being misidentified by the authentication server. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 200

A security analyst needs to ensure email domains that send phishing attempts without previous communications are not delivered to mailboxes. The following email headers are being reviewed: Which of the following is the best action for the security analyst to take?

Exhibit 1 for question 200
  • ABlock messages from hr-saas.com because it is not a recognized domain
  • BReroute all messages with unusual security warning notices to the IT administrator
  • CQuarantine all messages with sales-mail com in the email header (correct answer)
  • DBlock vendor com for repeated attempts to send suspicious messages
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Quarantine all messages with sales-mail com in the email header This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 201 Β· Select all that apply

After remote desktop capabilities were deployed in the environment various vulnerabilities were noticed: β€’ Exfiltration of intellectual property β€’ Unencrypted files β€’ Weak user passwords Which of the following is the best way to mitigate these vulnerabilities? (Choose two.)

  • AImplementing data loss prevention (correct answer)
  • BDeploying file integrity monitoring
  • CRestricting access to critical file services only
  • DDeploying directory-based group policies
  • EEnabling modem authentication that supports MFA (correct answer)
  • FImplementing a version control system
  • GImplementing a CMDB platform
Reveal answer & explanation
Correct answer: A, E

The correct answer is A, E. Option A: Implementing data loss prevention Option E: Enabling modem authentication that supports MFA

Explanation

Multifactor authentication combines independent authentication factors so one compromised credential is insufficient. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 202

A company recently experienced an incident in which an advanced threat actor was able to shim malicious code against the hardware stack of a domain controller. The forensic team cryptographically validated that both the underlying firmware of the box and the operating system had not been compromised. However, the attacker was able to exfiltrate information from the server using a steganographic technique within LDAP. Which of the following is the best way to reduce the risk of reoccurrence?

  • AEnforcing allow lists for authorized network ports and protocols (correct answer)
  • BMeasuring and attesting to the entire boot chain
  • CRolling the cryptographic keys used for hardware security modules
  • DUsing code signing to verify the source of OS updates
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Enforcing allow lists for authorized network ports and protocols

Topic 1 Β· Question 203

A user tried to access a web page at http://10.1.11. Previously the web page did not require authentication, and now the browser is prompting for credentials. Which of the following actions would best prevent the issue from reoccurring and reduce the likelihood of credential exposure?

  • AImplementing 802.1x EAP-TTLS on access points to reduce the risk of evil twins (correct answer)
  • BTransitioning internal services to use DNS security
  • CModifying web server configuration and utilizing X509 certificates for authentication
  • DInstalling new rules for the IDS to detect impersonation attacks
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Implementing 802.1x EAP-TTLS on access points to reduce the risk of evil twins

Explanation

TLS protects data in transit with authenticated encryption between network endpoints. 802.1X provides port-based network access control using a supplicant, authenticator, and authentication server.

Topic 1 Β· Question 204

Audit findings indicate several user endpoints are not utilizing full disk encryption. During the remediation process, a compliance analyst reviews the testing details for the endpoints and notes the endpoint device configuration does not support full disk encryption. Which of the following is the most likely reason the device must be replaced?

  • AThe HSM is outdated and no longer supported by the manufacturer
  • BThe vTPM was not properly initialized and is corrupt.
  • CThe HSM is vulnerable to common exploits and a firmware upgrade is needed
  • DThe motherboard was not configured with a TPM from the OEM supplier (correct answer)
  • EThe HSM does not support sealing storage
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: The motherboard was not configured with a TPM from the OEM supplier This option keeps traffic private / properly secured as required.

Showing questions 181–200 of 393 Β· Page 10 of 20