πŸ”

CAS-005 β€” questions

Page 2 of 20 Β· 393 total questions.

Topic 1 Β· Question 21

An internal user can send encrypted emails successfully to all recipients, except one. at an external organization. When the internal user attempts to send encrypted emails to this external recipient, a security error message appears. The issue does not affect unencrypted emails. The external recipient can send encrypted emails to internal users. Which of the following is the most likely cause of the issue?

  • AThe validity dates of the external recipient’s private key do not match the SSH keys with which the internal user is accessing the system.
  • BThe external recipient has an expired public/private key pair that has not been revoked by the CA.
  • CThe internal user's company email servers have an incorrect implementation of OCSP and CRL settings.
  • DThe external recipient's email address and the email address associated with the external recipient's public key are mismatched. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: The external recipient's email address and the email address associated with the external recipient's public key are mismatched. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 22

A security administrator is setting up a virtualization solution that needs to run services from a single host. Each service should be the only one running in its environment. Each environment needs to have its own operating system as a base but share the kernel version and properties of the running host. Which of the following technologies would best meet these requirements?

  • AContainers (correct answer)
  • BType 1 hypervisor
  • CType 2 hypervisor
  • DVirtual desktop infrastructure
  • EEmulation
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Containers

Explanation

A container packages an application and dependencies while sharing the host kernel for lightweight isolation. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 23

A company has data it would like to aggregate from its PLCs for data visualization and predictive maintenance purposes. Which of the following is the most likely destination for the tag data from the PLCs?

  • AExternal drive
  • BCloud storage
  • CSystem aggregator
  • DLocal historian (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Local historian

Topic 1 Β· Question 24

Which of the following is the best way to protect the website browsing history for an executive who travels to foreign countries where internet usage is closely monitored?

  • ADOH (correct answer)
  • BEAP-TLS
  • CGeofencing
  • DPrivate browsing mode
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: DOH

Topic 1 Β· Question 25

A systems administrator is working with the SOC to identify potential intrusions associated with ransomware. The SOC wants the systems administrator to perform network-level analysis to identify outbound traffic from any infected machines. Which of the following is the most appropriate action for the systems administrator to take?

  • AMonitor for IoCs associated with C&C communications.
  • BTune alerts to Identify changes to administrative groups.
  • CReview NetFlow logs for unexpected increases in egress traffic. (correct answer)
  • DPerform binary hash comparisons to identify infected devices.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Review NetFlow logs for unexpected increases in egress traffic.

Topic 1 Β· Question 26

A retail organization wants to properly test and verify its capabilities to detect and/or prevent specific TTPs as mapped to the MITRE ATTACK framework specific to APTs. Which of the following should be used by the organization to accomplish this goal?

  • ATabletop exercise
  • BPenetration test (correct answer)
  • CSandbox detonation
  • DHoneypot
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Penetration test

Explanation

A penetration test safely exploits weaknesses to demonstrate real impact and validate defenses.

Topic 1 Β· Question 27

IoCs were missed during a recent security incident due to the reliance on a signature-based detection platform. A security engineer must recommend a solution that can be implemented to address this shortcoming. Which of the following would be the most appropriate recommendation?

  • AFIM
  • BSASEC. UEBA
  • DCSPM (correct answer)
  • EEAP
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: CSPM This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 28 Β· Select all that apply

A company that provides services to clients who work with highly sensitive data would like to provide assurance that the data's confidentiality is maintained in a dynamic, low-risk environment. Which of the following would best achieve this goal? (Choose two.)

  • AInstall a SOAR on all endpoints.
  • BHash all files.
  • CInstall SIEM within a SOC.
  • DEncrypt all data and files at rest, in transit, and in use. (correct answer)
  • EConfigure SOAR to monitor and intercept files and data leaving the network. (correct answer)
  • FImplement file integrity monitoring.
Reveal answer & explanation
Correct answer: D, E

The correct answer is D, E. Option D: Encrypt all data and files at rest, in transit, and in use. Option E: Configure SOAR to monitor and intercept files and data leaving the network.

Topic 1 Β· Question 29

An organization wants to implement an access control system based on its data classification policy that includes the following data types: Confidential - Restricted - Internal - Public Flag for Review - The access control system should support SSO federation to map users into groups. Each group should only access systems that process and store data at the classification assigned to the group. Which of the following should the organization implement to enforce its requirements with a minimal impact to systems and resources?

  • AA tagging strategy in which all resources are assigned a tag based on the data classification type, and a system that enforces attribute-based access control (correct answer)
  • BRole-based access control that maps data types to internal roles, which are defined in the human resources department's source of truth system
  • CNetwork microsegmentation based on data types, and a network access control system enforcing mandatory access control based on the user principal
  • DA rule-based access control strategy enforced by the SSO system with rules managed by the internal LDAP and applied on a per-system basis
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: A tagging strategy in which all resources are assigned a tag based on the data classification type, and a system that enforces attribute-based access control

Topic 1 Β· Question 30

A security analyst was monitoring the networks of a group of companies. The analyst identified several periods of concentrated, coordinated activity by unknown actors. The activity repeated at regular intervals and affected all the companies. Minor hardware outages that correlated with the same times as the discovered activity escalated in severity. Which of the following threat actors was most likely involved?

  • AAn organized crime collective running a ransomware campaign
  • BA group of politically motivated hackers
  • CDisgruntled employees who were recently terminated
  • DAn advanced persistent threat financed by a nation-state (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: An advanced persistent threat financed by a nation-state

Explanation

Network address translation maps addresses between networks and commonly lets private hosts share public connectivity. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 31

The company's client service team is receiving a large number of inquiries from clients regarding a new vulnerability. Which of the following would provide the customer service team with a consistent message to deliver directly to clients?

  • ACommunication plan (correct answer)
  • BResponse playbook
  • CDisaster recovery procedure
  • DAutomated runbook
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Communication plan

Topic 1 Β· Question 32

A company wants to use a process to embed a sign of ownership covertly inside a proprietary document without adding any identifying attributes. Which of the following would be best to use as part of the process to support copyright protections of the document?

  • ASteganography (correct answer)
  • BE-signature
  • CWatermarking
  • DCryptography
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Steganography

Topic 1 Β· Question 33

Which of the following utilizes policies that route packets to ensure only specific types of traffic are being sent to the correct destination based on application usage?

  • ASDN (correct answer)
  • Bpcap
  • Cvmstat
  • DDNSSEC
  • EVPC
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: SDN

Topic 1 Β· Question 34 Β· Select all that apply

An incident response team completed recovery from offline backup for several workstations. The workstations were subjected to a ransomware attack after users fell victim to a spear-phishing campaign, despite a robust training program. Which of the following questions should be considered during the lessons-learned phase to most likely reduce the risk of reoccurrence? (Choose two.)

  • AAre there opportunities for legal recourse against the originators of the spear-phishing campaign?
  • BWhat internal and external stakeholders need to be notified of the breach?
  • CWhich methods can be implemented to increase speed of offline backup recovery?
  • DWhat measurable user behaviors were exhibited that contributed to the compromise? (correct answer)
  • EWhich technical controls, if implemented, would provide defense when user training fails? (correct answer)
  • FWhich user roles are most often targeted by spear phishing attacks?
Reveal answer & explanation
Correct answer: D, E

The correct answer is D, E. Option D: What measurable user behaviors were exhibited that contributed to the compromise? Option E: Which technical controls, if implemented, would provide defense when user training fails?

Topic 1 Β· Question 35

Two companies that recently merged would like to unify application access between the companies, without initially merging internal authentication stores. Which of the following technical strategies would best meet this objective?

  • AFederation (correct answer)
  • BRADIUS
  • CTACACS+
  • DMFA
  • EABAC
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Federation

Topic 1 Β· Question 36

An analyst needs to evaluate all images and documents that are publicly shared on a website. Which of the following would be the best tool to evaluate the metadata of these files?

  • AOllyDbg
  • BExifTool (correct answer)
  • CVolatility
  • DGhidra
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: ExifTool

Topic 1 Β· Question 37

An organization has deployed a cloud-based application that provides virtual event services globally to clients. During a typical event, thousands of users access various entry pages within a short period of time. The entry pages include sponsor-related content that is relatively static and is pulled from a database. When the first major event occurs, users report poor response time on the entry pages. Which of the following features is the most appropriate for the company to implement?

  • AHorizontal scalability
  • BVertical scalability
  • CContainerization
  • DStatic code analysis
  • ECaching (correct answer)
Reveal answer & explanation
Correct answer: E

The correct answer is E. Option E: Caching

Topic 1 Β· Question 38

An organization's board of directors has asked the Chief Information Security Officer to build a third-party management program. Which of the following best explains a reason for this request?

  • ARisk transference
  • BSupply chain visibility (correct answer)
  • CSupport availability
  • DVulnerability management
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Supply chain visibility This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 39

A company is rewriting a vulnerable application and adding the mprotect() system call in multiple parts of the application's code that was being leveraged by a recent exploitation tool. Which of the following should be enabled to ensure the application can leverage the new system call against similar attacks in the future?

  • ATPM
  • BSecure boot
  • CNX bit (correct answer)
  • DHSM
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: NX bit

Topic 1 Β· Question 40

Which of the following items should be included when crafting a disaster recovery plan?

  • ARedundancy
  • BTesting exercises (correct answer)
  • CAutoscaling
  • DCompetitor locations
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Testing exercises By spanning multiple Availability Zones / adding redundancy, this option provides the high availability and resilience required.

Showing questions 21–40 of 393 Β· Page 2 of 20