🔍

CAS-005 — questions

Page 12 of 20 · 393 total questions.

Topic 1 · Question 225

A university issues badges through a homegrown identity management system to all staff and students. Each week during the summer, temporary summer school students arrive and need to be issued a badge to access minimal campus resources. The security team received a report from an outside auditor indicating the homegrown system is not consistent with best practices in the security field. Which of the following should the security team recommend first?

  • AInvestigating a potential threat identified in logs related to the identity management system
  • BUpdating the identity management system to use discretionary access control
  • CBeginning research on two-factor authentication to later introduce into the identity management system
  • DWorking with procurement and creating a requirements document to select a new IAM system/vendor (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Working with procurement and creating a requirements document to select a new IAM system/vendor This option keeps traffic private / properly secured as required.

Topic 1 · Question 226

Due to budget constraints, an organization created a policy that only permits vulnerabilities rated high and critical according to CVSS to be fixed or mitigated. A security analyst notices that many vulnerabilities that were previously scored as medium are now breaching higher thresholds. Upon further investigation, the analyst notices certain ratings are not aligned with the approved system categorization. Which of the following can the analyst do to get a better picture of the risk while adhering to the organization’s policy?

  • AAlign the exploitability metrics to the predetermined system categorization.
  • BAlign the remediation levels to the predetermined system categorization.
  • CAlign the impact subscore requirements to the predetermined system categorization. (correct answer)
  • DAlign the attack vectors to the predetermined system categorization.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Align the impact subscore requirements to the predetermined system categorization. This option keeps traffic private / properly secured as required.

Topic 1 · Question 227

An IT department is currently working to implement an enterprise DLP solution. Due diligence and best practices must be followed in regard to mitigating risk. Which of the following ensures that authorized modifications are well planned and executed?

  • ARisk management
  • BNetwork management
  • CConfiguration management
  • DChange management (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Change management

Topic 1 · Question 228

A security architect wants to prevent security impacts from input into data fields, such as the following: 'AND 1=1# Which of the following would best accomplish this objective?

  • AAPIs
  • BCoding standards (correct answer)
  • CBase64 encoding
  • DSandboxing
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Coding standards This option keeps traffic private / properly secured as required.

Topic 1 · Question 229

A software development company needs to mitigate third-party risks to its software supply chain. Which of the following techniques should the company use in the development environment to best meet this objective?

  • APerforming software composition analysis (correct answer)
  • BRequiring multifactor authentication
  • CEstablishing coding standards and monitoring for compliance
  • DImplementing a robust unit and regression-testing scheme
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Performing software composition analysis

Topic 1 · Question 230 · Select all that apply

A mobile device hardware manufacturer receives the following requirements from a company that wants to produce and sell a new mobile platform: • The platform should store biometric data. • The platform should prevent unapproved firmware from being loaded. • A tamper-resistant, hardware-based counter should track if unapproved firmware was loaded. Which of the following should the hardware manufacturer implement? (Choose three).

  • AASLR
  • BNX
  • CeFuse (correct answer)
  • DSED
  • ESELinux
  • FSecure boot (correct answer)
  • GShell restriction
  • HSecure enclave (correct answer)
Reveal answer & explanation
Correct answer: C, F, H

The correct answer is C, F, H. Option C: eFuse Option F: Secure boot Option H: Secure enclave

Topic 1 · Question 231

Based on a recent security audit, a company discovered the perimeter strategy is inadequate for its recent growth. To address this issue, the company is looking for a solution that includes the following requirements: • Collapse of multiple network security technologies into a single footprint • Support for multiple VPNs with different security contexts • Support for application layer security (Layer 7 of the OSI Model) Which of the following technologies would be the most appropriate solution given these requirements?

  • ANAT gateway
  • BReverse proxy
  • CNGFW (correct answer)
  • DNIDS
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: NGFW This option keeps traffic private / properly secured as required.

Topic 1 · Question 232 · Select all that apply

A security engineer needs to select the architecture for a cloud database that will protect an organization’s sensitive data. The engineer has a choice between a single-tenant or a multitenant database architecture offered by a cloud vendor. Which of the following best describes the security benefits of the single-tenant option? (Choose two.)

  • AMost cost-effective
  • BEase of backup and restoration
  • CHigh degree of privacy (correct answer)
  • DLow resilience to side-channel attacks
  • EFull control and ability to customize (correct answer)
  • FIncreased geographic diversity
Reveal answer & explanation
Correct answer: C, E

The correct answer is C, E. Option C: High degree of privacy Option E: Full control and ability to customize This option keeps traffic private / properly secured as required.

Topic 1 · Question 233

A penetration tester discovers a condition that causes unexpected behavior in a web application. This results in the dump of the interpreter’s debugging information, which includes the interpreter’s version, full path of binary files, and the user ID running the process. Which of the following actions would best mitigate this risk?

  • AInclude routines in the application for message handling. (correct answer)
  • BAdopt a compiled programming language instead.
  • CPerform SAST vulnerability scans on every build.
  • DValidate user-generated input.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Include routines in the application for message handling.

Topic 1 · Question 234

A security architect is analyzing an old application that is not covered for maintenance anymore because the software company is no longer in business. Which of the following techniques should have been implemented to prevent these types of risks?

  • ACode reviews
  • BSupply chain visibility
  • CSoftware audits
  • DSource code escrows (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Source code escrows This option keeps traffic private / properly secured as required.

Topic 1 · Question 235

To bring digital evidence in a court of law, the evidence must be:

  • Amaterial. (correct answer)
  • Btangible.
  • Cconsistent.
  • Dconserved.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: material.

Topic 1 · Question 236

An organization is looking to establish more robust security measures by implementing PKI. Which of the following should the security analyst implement when considering mutual authentication?

  • APerfect forward secrecy on both endpoints
  • BShared secret for both endpoints
  • CPublic keys on both endpoints (correct answer)
  • DA common public key on each endpoint
  • EA common private key on each endpoint
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Public keys on both endpoints This option keeps traffic private / properly secured as required.

Topic 1 · Question 237

A cyberanalyst has been tasked with recovering PDF files from a provided image file. Which of the following is the best file-carving tool for PDF recovery?

  • Aobjdump
  • BStrings
  • Cdd
  • DForemost (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Foremost

Topic 1 · Question 238

An organization handles sensitive information that must be displayed on call center technicians’ screens to verify the identities of remote callers. The technicians use three randomly selected fields of information to complete the identity verification process. Some of the fields contain PII that are unique identifiers for the remote callers. Which of the following should be implemented to identify remote callers while also reducing the risk that technicians could improperly use the identification information?

  • AData masking (correct answer)
  • BEncryption
  • CTokenization
  • DScrubbing
  • ESubstitution
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Data masking

Topic 1 · Question 239

A junior developer is informed about the impact of new malware on an Advanced RISC Machine (ARM) CPU, and the code must be fixed accordingly. Based on the debug, the malware is able to insert itself in another process memory location. Which of the following technologies can the developer enable on the ARM architecture to prevent this type of malware?

  • AExecute never (correct answer)
  • BNo-execute
  • CTotal memory encryption
  • DVirtual memory protection
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Execute never

Topic 1 · Question 240

An analyst has prepared several possible solutions to a successful attack on the company. The solutions need to be implemented with the least amount of downtime. Which of the following should the analyst perform?

  • AImplement all the solutions at once in a virtual lab and then run the attack simulation. Collect the metrics and then choose the best solution based on the metrics.
  • BImplement every solution one at a time in a virtual lab, running a metric collection each time. After the collection, run the attack simulation, roll back each solution, and then implement the next. Choose the best solution based on the best metrics.
  • CImplement every solution one at a time in a virtual lab, running an attack simulation each time while collecting metrics. Roll back each solution and then implement the next. Choose the best solution based on the best metrics. (correct answer)
  • DImplement all the solutions at once in a virtual lab and then collect the metrics. After collection, run the attack simulation. Choose the best solution based on the best metrics.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Implement every solution one at a time in a virtual lab, running an attack simulation each time while collecting metrics. Roll back each solution and then implement the next. Choose the best solution based on the best...

Topic 1 · Question 241

A security architect examines a section of code and discovers the following: char username[20] char password[20] gets(username) checkUserExists(username) Which of the following changes should the security architect require before approving the code for release?

  • AAllow only alphanumeric characters for the username.
  • BMake the password variable longer to support more secure passwords.
  • CPrevent more than 20 characters from being entered. (correct answer)
  • DAdd a password parameter to the checkUserExists function.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Prevent more than 20 characters from being entered. This option keeps traffic private / properly secured as required.

Topic 1 · Question 242

A security manager is creating a connection between two networks that process data at different classification levels. The main goal of this connection is to pass data from the higher classification side to the lower classification side without causing spillage. Only approved fie types and content will be allowed. Which of the following technologies would best meet this objective?

  • ANetwork access control
  • BFile integrity monitoring
  • CCross-domain solution (correct answer)
  • DMicrosegmentation
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Cross-domain solution This option keeps traffic private / properly secured as required.

Topic 1 · Question 243

A security consultant has been asked to identify a simple, secure solution for a small business with a single access point. A single SSID and no guest access will be used. The customer facility is located in a crowded area of town. The customer has asked that the solution require low administrative overhead. Which of the following should the security consultant recommend?

  • AWPA3-Personal (correct answer)
  • BWPA2-TKIP
  • CWPA2-Enterprise
  • DWPA3-Enterprise
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: WPA3-Personal

Explanation

WPA3 strengthens wireless authentication and encryption compared with earlier Wi-Fi security standards. This option keeps traffic private / properly secured as required.

Topic 1 · Question 244

A security team is concerned with attacks that are taking advantage of return-oriented programming against the company’s public-facing applications. Which of the following should the company implement on the public-facing servers?

  • AIDS
  • BASLR (correct answer)
  • CTPM
  • DHSM
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: ASLR This option keeps traffic private / properly secured as required.

Showing questions 221240 of 393 · Page 12 of 20