πŸ”

CAS-005 β€” questions

Page 20 of 20 Β· 393 total questions.

Topic 1 Β· Question 386

A security analyst is designing a network structure to support a virtual server that is running an unsupported operating system The unsupported operating system contains PII and is business critical. Given the following information: β€’ The PII server name is legacy-box, and the machine IP is 192.168.1.100. β€’ The jump-box server name is jump-box with an IP of 192.168.1.10 β€’ The IP address scheme for the corporate network is 192.168.1.0/24 The machines with the following IP addresses need access β€’ 192.168.1.3 β€’ 192.168.1.4 Which of the following actions should the analyst do to best secure the PII server?

  • AConfigure jump-box and legacy-box with dual NICs, giving them both virtual network and corporate network IP addresses
  • BModify host firewall rules and routes on legacy-box to permit only 192.168.1.3 and 192.168.1.4 to RDP
  • CSet up host firewall rules and routes on jump-box to permit only 192.168.1.3 and 192.168.1.4 to RDP
  • DImplement host firewall rules and routes on legacy-box to permit only 192.168.1.0/24 to RDP and deny everything else (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Implement host firewall rules and routes on legacy-box to permit only 192.168.1.0/24 to RDP and deny everything else

Explanation

A firewall enforces traffic policy by permitting or blocking connections based on configured rules. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 387

A pharmaceutical company employs automated control systems to fabricate chemicals. During a recent experiment to attempt to secure these systems, a security engineer finds that the controllers do not appear to be sensitive to additional network latency. Which of the following is the best recommendation for this issue?

  • APerforming integrity checks on control system command journals
  • BPerforming baseline reviews on the system configurations
  • CIntegrating a proxy to drop improperly formatted commands (correct answer)
  • DImplementing in-line encryption between the control systems
  • EDeploying and configuring a protocol accelerator
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Integrating a proxy to drop improperly formatted commands This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 388

A security engineer is reviewing a security incident in which an employee account was compromised. The engineer notes the following activity after reviewing the logs: Which of the following is the best way to reduce the probability of a future compromise?

Exhibit 1 for question 388
  • AUsing a different third-party MFA vendor
  • BConfiguring password complexity to include special characters
  • CImplementing conditional access across the organization (correct answer)
  • DIncreasing the rotation rate of account credentials
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Implementing conditional access across the organization This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 389

An application security engineer is examining the IAM configuration for a workload. The following is a sample of the decoded payload and header: Which of the following is the most concerning risk?

Exhibit 1 for question 389
  • ALateral movement
  • BPrivilege escalation
  • CCredential stuffing (correct answer)
  • DRCE from deserialization
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Credential stuffing This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 390

A security engineer must reduce overhead of routine security administration tasks with SOAR. Which of the following should the engineer do to best meet this objective?

  • APerform static analysis of potentially malicious software. (correct answer)
  • BEnrich data based on threat intelligence feeds
  • CApply context-based access restrictions at scale
  • DChange the enterprise password policy requirements
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Perform static analysis of potentially malicious software. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 391

An organization receives intelligence information about a foreign adversary targeting instances of a web server application that the organization uses. The information includes: β€’ The originating IP addresses of the attack β€’ The common commands run on the affected device β€’ The indicators that a device has been affected β€’ The actions that can be taken on the device to stop the attack Which of the following should the organization do first?

  • ADraft an incident response playbook
  • BBuild tactics, techniques, and procedures
  • CCreate Snort and YARA rules (correct answer)
  • DConfigure user behavior analytics
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Create Snort and YARA rules

Topic 1 Β· Question 392

A multinational enterprise is planning to implement a centralized authentication solution across its global offices. The risk team identifies that some regional offices operate in areas with high latency and some data centers experience intermittent connectivity issues. The Chief Information Officer requests a solution that minimizes authentication disruptions without compromising security. Which of the following is the best risk treatment strategy?

  • AImplement a hybrid identity solution with local failover authentication (correct answer)
  • BRequire that all users authenticate only during on-site visits to headquarters
  • CAccept the risk due to the low probability of simultaneous authentication failures
  • DOutsource authentication to a third-party cloud provider
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Implement a hybrid identity solution with local failover authentication This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 393

A security engineer wants to improve the security of an application as part of the development pipeline. The engineer reviews the following component of an internally developed web application that allows employees to manipulate documents from a number of internal servers. response = requests.get(url) Users can specify the document to be parsed by passing the document URL to the application as a parameter. Which of the following is the best solution to verify the quality and security of this component?

  • AIndexing (correct answer)
  • BOutput encoding
  • CCode scanner
  • DPenetration testing
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Indexing This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 395

An organization that utilizes token-based access for all facilities and systems recently completed an annual review of its security controls. Given the following report: Which of the following is the most important residual risk factor?

Exhibit 1 for question 395
  • ANon-repudiation
  • BToken availability (correct answer)
  • CAttestation
  • DSystems monitoring
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Token availability This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 396

A Chief Information Security Officer (CISO) is developing a third-party risk management program and wants to establish an order of preference for solicitation and acceptance of audit and assessment results from business partners. The CISO prefers a formal certification against an established framework, which should be considered more reliable than self-attestations. Which of the following is most likely the reason for this perspective?

  • ACertifications are typically issued against a formal standard.
  • BAssessments are based on evidence, not judgments.
  • CFor standards like PCI. self-attestations are more reliable than certifications.
  • DA certification audit is managed by a central authority. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: A certification audit is managed by a central authority. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 397

Which of the following preconditions must be met in order for homomorphic encryption to become practical in mainstream data-in-use applications?

  • AAvailability of updated ECC curves that provide quantum resistance (correct answer)
  • BCoprocessors made available with more appropriate security extensions
  • CFinalization of a standard PQC suite of lattice- and code-based algorithms
  • DCapability to run the most advanced LLMs while disconnected from the internet
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Availability of updated ECC curves that provide quantum resistance This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 398

A penetration tester reviews the following output: Which of the following mitigations should the security engineer recommend?

Exhibit 1 for question 398
  • ARemoving domain users from the administrator group on the reporting server
  • BDisabling NTLM hash transmission over the network to prevent sniffing (correct answer)
  • CBlocking the Kerberos protocol on servers that are shared by many users
  • DImplementing password complexity requirements in the domain
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Disabling NTLM hash transmission over the network to prevent sniffing This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 399

A company receives several complaints from customers regarding its website. An engineer implements a parser for the web server logs that generates the following output: Which of the following should the company implement to best resolve the issue?

Exhibit 1 for question 399
  • AIDS
  • BCDN (correct answer)
  • CWAF
  • DNAC
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: CDN

Showing questions 381–393 of 393 Β· Page 20 of 20