πŸ”

CAS-005 β€” questions

Page 14 of 20 Β· 393 total questions.

Topic 1 Β· Question 265

An auditor is reviewing the logs from a web application to determine the source of an incident. The web application architecture includes an internet-accessible application load balancer, a number of web servers in a private subnet, application servers, and one database server in a tiered configuration. The application load balancer cannot store the logs. The following are sample log snippets: Which of the following should the auditor recommend to ensure future incidents can be traced back to the sources?

Exhibit 1 for question 265
  • AEnable the X-Forwarded-For header at the load balancer. (correct answer)
  • BInstall a software-based HIDS on the application servers.
  • CInstall a certificate signed by a trusted CA.
  • DUse stored procedures on the database server.
  • EStore the value of the $_SERVER['REMOTE_ADDR'] received by the web servers.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Enable the X-Forwarded-For header at the load balancer.

Explanation

A load balancer distributes requests across healthy backends to improve scale and availability. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 266

An organization that performs real-time financial processing is implementing a new backup solution. Given the following business requirements: β€’ The backup solution must reduce the risk for potential backup compromise β€’ The backup solution must be resilient to a ransomware attack β€’ The time to restore from backups is less important than the backup data integrity β€’ Multiple copies of production data must be maintained. Which of the following backup strategies best meets these requirements?

  • ACreating a secondary, immutable database and adding live data on a continuous basis (correct answer)
  • BUtilizing two connected storage arrays and ensuring the arrays constantly sync
  • CEnabling remote journaling on the databases to ensure real-time transactions are mirrored
  • DSetting up anti-tampering on the databases to ensure data cannot be changed unintentionally
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Creating a secondary, immutable database and adding live data on a continuous basis By spanning multiple Availability Zones / adding redundancy, this option provides the high availability and resilience required.

Topic 1 Β· Question 267

A system of globally distributed certificate servers connected to HSMs provide certificate security services for a publicly available PKI. These services include OCSP, certificate revocation list issuance, and certificate signing/issuance. The HSMs are all physical devices. All other servers are virtualized. Each global site has a network load balancer, and the sites are configured to load balance between sites. Users report occasional but persistent log-on failures to different PKI-enabled websites. There is no apparent pattern to the failures. Some OCSP responses must be signed by the HSM. Each HSM is connected to a physical server containing multiple VMs for the local site with CAT 6e network cable. The backplane connecting the VMs is fiber based. Which of the following would best reduce the OCSP response time in order to rule out the connection between the certificate server and HSM as a cause of the user-reported issues?

  • AVirtualize the HSMs and convert the virtualized servers to physical systems.
  • BReplace the copper-based network infrastructure with fiber. (correct answer)
  • CShorten the time the duration certificates are valid to 72 hours and implement ACME.
  • DReduce the number of global sites while increasing the number of HSMs.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Replace the copper-based network infrastructure with fiber. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 268 Β· Select all that apply

An administrator brings the company's fleet of mobile devices into its PKI in order to align device WLAN NAC configurations with existing workstations and laptops. Thousands of devices need to be reconfigured in a cost-effective, time-efficient, and secure manner. Which of the following actions best achieve this goal? (Choose two.)

  • AUsing the existing MDM solution to integrate with directory services for authentication and enrollment (correct answer)
  • BDeploying netAuth extended key usage certificate templates
  • CDeploying serverAuth extended key usage certificate templates
  • DDeploying clientAuth extended key usage certificate templates
  • EConfiguring SCEP on the CA with an OTP for bulk device enrollment (correct answer)
  • FSubmitting a CSR to the CAto obtain a single certificate that can be used across all devices
Reveal answer & explanation
Correct answer: A, E

The correct answer is A, E. Option A: Using the existing MDM solution to integrate with directory services for authentication and enrollment Option E: Configuring SCEP on the CA with an OTP for bulk device enrollment This option delivers the requirement at the lowest cost.

Topic 1 Β· Question 269

The ISAC for the retail industry recently released a report regarding social engineering tactics in which small groups create distractions for employees while other malicious individuals install advanced card skimmers on the payment systems. The Chief Information Security Officer (CISO) thinks that security awareness training, technical control implementations, and governance already in place is adequate to protect from this threat. The board would like to test these controls. Which of the following should the CISO recommend?

  • ADark web monitoring
  • BAdversary emulation engagement (correct answer)
  • CSupply chain risk consultation
  • DTabletop exercises
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Adversary emulation engagement This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 270

A company finds logs with modified time stamps when compared to other systems. The security team decides to improve logging and auditing for incident response. Which of the following should the team do to best accomplish this goal?

  • AIntegrate a file-monitoring tool with the SIEM.
  • BChange the log solution and integrate it with the existing SIEM.
  • CImplement a central logging server, allowing only log ingestion. (correct answer)
  • DRotate and back up logs every 24 hours, encrypting the backups.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Implement a central logging server, allowing only log ingestion. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 271

A company recently experienced a ransomware attack. Although the company performs systems and data backup on a schedule that aligns with its RPO requirements, the backup administrator could not recover critical systems and data from its offline backups to meet the RPO. Eventually, the systems and data were restored with information that was six months outside of RPO requirements. Which of the following actions should the company take to reduce the risk of a similar attack?

  • AEncrypt and label the backup tapes with the appropriate retention schedule before they are sent to the off-site location.
  • BImplement a business continuity process that includes reverting manual business processes.
  • CPerform regular disaster recovery testing of IT and non-IT systems and process. (correct answer)
  • DCarry out a tabletop exercise to update and verify the RACI matrix with IT and critical business functions.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Perform regular disaster recovery testing of IT and non-IT systems and process.

Topic 1 Β· Question 272

An organization hires a security consultant to establish a SOC that includes a threat-modeling function. During initial activities, the consultant works with system engineers to identify antipatterns within the environment. Which of the following is most critical for the engineers to disclose to the consultant during this phase?

  • AResults from the most recent infrastructure access review
  • BA listing of unpatchable IoT devices in use in the data center
  • CNetwork and data flow diagrams covering the production environment (correct answer)
  • DResults from the most recent software composition analysis
  • EA current inventory of cloud resources and SaaS products in use
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Network and data flow diagrams covering the production environment This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 273

In a recent audit, several critical legacy systems, which are externally exposed so that a specific vendor can manage them remotely, were identified. These systems must remain available to the vendor for the next six months. A security team segmented the network so these systems can only communicate with internal resources. Which of the following actions would be most appropriate to restore the vendor's access to manage these systems?

  • ADisable all connections to the systems, and implement a backup solution to capture the needed data to send to the vendor on a weekly basis.
  • BCreate a VPN connection and set up firewall rules so only specific connections are allowed to those systems. (correct answer)
  • CDisable external connections to those systems for the next six months.
  • DIsolate the critical systems so they can only be remotely managed from the internet.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Create a VPN connection and set up firewall rules so only specific connections are allowed to those systems.

Explanation

A VPN creates an encrypted tunnel across an untrusted network for private remote or site connectivity. A firewall enforces traffic policy by permitting or blocking connections based on configured rules. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 274

While investigating an email server that crashed, an analyst reviews the following log files: Which of the following is most likely the root cause?

Exhibit 1 for question 274
  • AThe administrator's account credentials were intercepted and reused.
  • BThe backup process did not complete and caused cascading failure.
  • CA hardware failure in the storage array caused the mailboxes to be inaccessible.
  • DA user with low privileges was able to escalate and erase all mailboxes. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: A user with low privileges was able to escalate and erase all mailboxes.

Topic 1 Β· Question 275

An incident response analyst finds the following content inside of a log file that was collected from a compromised server: Which of the following is the best action to prevent future compromise?

Exhibit 1 for question 275
  • ABlocking the processing of external files by forwarding them to another server for processing
  • BImplementing an allow list for all text boxes throughout the web application
  • CFiltering inserted characters for all user inputs and allowing only ASCII characters
  • DImproving file-parsing capabilities to stop external entities from executing commands (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Improving file-parsing capabilities to stop external entities from executing commands

Topic 1 Β· Question 276 Β· Select all that apply

A company isolates its ОВ systems from other areas of the corporate network. These systems are required to report usage information over the internet to the vendor. Which of the following best prevents compromise or sabotage? (Choose two.)

  • AImplementing allow lists (correct answer)
  • BMonitoring network behaviors
  • CEncrypting data at rest
  • DPerforming boot integrity checks
  • EExecuting daily health checks
  • FImplementing a site-to-site IPSec VPN (correct answer)
Reveal answer & explanation
Correct answer: A, F

The correct answer is A, F. Option A: Implementing allow lists Option F: Implementing a site-to-site IPSec VPN

Explanation

A VPN creates an encrypted tunnel across an untrusted network for private remote or site connectivity. An intrusion prevention system detects and actively blocks malicious traffic inline.

Topic 1 Β· Question 277

An organization is implementing Zero Trust architecture. A systems administrator must increase the effectiveness of the organization's context-aware access system. Which of the following is the best way to improve the effectiveness of the system?

  • ASecure zone architecture
  • BAlways-on VPN
  • CRADIUS
  • DMicrosegmentation (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Microsegmentation

Topic 1 Β· Question 278 Β· Select all that apply

A company plans to deploy a new online application that provides video training for its customers. As part of the design, the application must be: β€’ Fast for all users β€’ Available for users worldwide β€’ Protected against attacks Which of the following are the best components the company should use to meet these requirements? (Choose two.)

  • AWAF (correct answer)
  • BIPS
  • CCDN (correct answer)
  • DSASE
  • EVPN
  • FCASB
Reveal answer & explanation
Correct answer: A, C

The correct answer is A, C. Option A: WAF Option C: CDN

Topic 1 Β· Question 279

During a security review for the CI/CD process, a security engineer discovers the following information in a testing repository from the company: Which of the following options is the best countermeasure to prevent this issue in the future?

Exhibit 1 for question 279
  • APerforming an application penetration test over the testing environment before moving to production
  • BChanging the repository technology to avoid inclusion of confidential information
  • CAutomating the upload process of code to the repository and improving the software development life cycle
  • DUsing a secrets management platform to share and manage confidential information (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Using a secrets management platform to share and manage confidential information This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 280

A company must meet the following security requirements when implementing controls in order to be compliant with government policy: β€’ Access to the system document repository must be MFA enabled. β€’ Ongoing risk monitoring must be displayed on a system dashboard. β€’ Staff must receive email notifications about periodic tasks. Which of the following best meets all of these requirements?

  • AImplementing a GRC tool (correct answer)
  • BConfiguring a privileged access management system
  • CLaunching a vulnerability management program
  • DCreating a risk register
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Implementing a GRC tool This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 281

Based on the results of a SAST report on a legacy application, a security engineer is reviewing the following snippet of code flagged as vulnerable: Which of the following is the vulnerable line of code that must be changed?

Exhibit 1 for question 281
  • ALine [02]
  • BLine [04]
  • CLine [07]
  • DLine [08]
  • ELine [10] (correct answer)
Reveal answer & explanation
Correct answer: E

The correct answer is E. Option E: Line [10] This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 282

A company detects suspicious activity associated with inbound connections. Security detection tools are unable to categorize this activity. Which of the following is the best solution to help the company overcome this challenge?

  • AImplement an interactive honeypot.
  • BMap network traffic to known IoCs.
  • CMonitor the dark web.
  • DImplement UEBA. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Implement UEBA. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 283

After discovering that an employee is using a personal laptop to access highly confidential data, a systems administrator must secure the company's data. Which of the following capabilities best addresses this situation?

  • AOCSP stapling
  • BCASB
  • CSOAR
  • DConditional access (correct answer)
  • EPackage monitoring
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Conditional access This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 284

An organization is increasing its focus on training that addresses new social engineering and phishing attacks. Which of the following is the organization most concerned about?

  • AMeeting existing regulatory compliance
  • BOverreliance on AI support bots
  • CGenerative AI tools increasing the quality of exploits (correct answer)
  • DDifferential analysis using AI models
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Generative AI tools increasing the quality of exploits

Showing questions 261–280 of 393 Β· Page 14 of 20