πŸ”

CAS-005 β€” questions

Page 9 of 20 Β· 393 total questions.

Topic 1 Β· Question 165

A hospital provides tablets to its medical staff to enable them to more quickly access and edit patients' charts. The hospital wants to ensure that if a tablet is identified as lost or stolen and a remote command is issued, the risk of data loss can be mitigated within seconds. The tablets are configured as follows to meet hospital policy: β€’ Full disk encryption is enabled. β€’ "Always On" corporate VPN is enabled. β€’ eFuse-backed keystore is enabled/ready. β€’ Wi-Fi 6 is configured with SAE. β€’ Location services is disabled. β€’ Application allow list is unconfigured. Assuming the hospital policy cannot be changed, which of the following is the best way to meet the hospital's objective?

  • ARevoke the user VPN and Wi-Fi certificates
  • BCryptographically erase FDE volumes (correct answer)
  • CIssue new MFA credentials to all users
  • DConfigure the application allow list
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Cryptographically erase FDE volumes This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 166 Β· Select all that apply

A compliance officer is facilitating a business impact analysis and wants business unit leaders to collect meaningful data. Several business unit leaders want more information about the types of data the officer needs. Which of the following data types would be the most beneficial for the compliance officer? (Choose two.)

  • AInventory details
  • BApplicable contract obligations
  • CCosts associated with downtime (correct answer)
  • DNetwork diagrams
  • EContingency plans
  • FCritical processes (correct answer)
Reveal answer & explanation
Correct answer: C, F

The correct answer is C, F. Option C: Costs associated with downtime Option F: Critical processes

Topic 1 Β· Question 167

An ISAC supplied recent threat intelligence information about pictures used on social media that provide reconnaissance of systems in use in secure facilities. In response, the Chief Information Security Officer (CISO) wants several configuration changes implemented via the MDM to ensure the following: β€’ Camera functions and location services are blocked for corporate mobile devices. β€’ All social media is blocked on the corporate and guest wireless networks. Which of the following is the CISO practicing to safeguard against the threat?

  • AAdversary emulation
  • BOperational security (correct answer)
  • COpen-source intelligence
  • DSocial engineering
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Operational security This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 168

A company needs to define a new road map for improving secure coding practices in the software development life cycle and implementing better security standards. Which of the following is the best way for the company to achieve this goal?

  • APerforming a Software Assurance Maturity Model assessment and generating a road map as a final result (correct answer)
  • BConducting a threat-modeling exercise for the main applications and developing a road map based on the necessary security implementations
  • CDeveloping a new road map, including secure coding best practices, based on the security area road map and annual goals defined by the Chief Information Security Officer
  • DUsing the best practices in the OWASP secure coding manual to define a new road map
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Performing a Software Assurance Maturity Model assessment and generating a road map as a final result This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 169

A security architect wants to develop a baseline of security configurations. These configurations automatically will be utilized every time a new virtual machine is created. Which of the following technologies should the security architect deploy to accomplish this goal?

  • ASnort
  • BCASΠ’
  • CAnsible (correct answer)
  • DCMDB
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Ansible This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 170

A company wants to modify its process to comply with privacy requirements after an incident involving PII data in a development environment. In order to perform functionality tests, the QA team still needs to use valid data in the specified format. Which of the following best addresses the risk without impacting the development life cycle?

  • AEncrypting the data before moving Into the QA environment
  • BTruncating the data to make it not personally identifiable
  • CUsing a large language model to generate synthetic data
  • DUtilizing tokenization for sensitive fields (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Utilizing tokenization for sensitive fields

Topic 1 Β· Question 171

A global organization is reviewing potential vendors to outsource a critical payroll function. Each vendor's plan includes using local resources in multiple regions to ensure compliance with all regulations. The organization's Chief Information Security Officer is conducting a risk assessment on the potential outsourcing vendors' subprocessors. Which of the following best explains the need for this risk assessment?

  • ARisk mitigations must be more comprehensive than the existing payroll provider.
  • BDue care must be exercised during all procurement activities.
  • CThe responsibility of protecting PII remains with the organization. (correct answer)
  • DSpecific regulatory requirements must be met in each jurisdiction.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: The responsibility of protecting PII remains with the organization. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 172

An organization plans to deploy new software. The project manager compiles a list of roles that will be involved in different phases of the deployment life cycle. Which of the following should the project manager use to track these roles?

  • ACMDB
  • BRecall tree
  • CITIL
  • DRACI matrix (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: RACI matrix

Topic 1 Β· Question 173

An organization decides to move to a distributed workforce model. Several legacy systems exist on premises and cannot be migrated because of existing compliance requirements. However, all new systems are required to be cloud-based. Which of the following would best ensure network access security?

  • AUtilizing a VPN for all users who require legacy system access (correct answer)
  • BShifting all legacy systems to the existing public cloud infrastructure
  • CConfiguring an SDN to block malicious traffic to on-premises networks
  • DDeploying microsegmentation with a firewall acting as the core router
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Utilizing a VPN for all users who require legacy system access

Explanation

A VPN creates an encrypted tunnel across an untrusted network for private remote or site connectivity. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 174

An organization recently acquired another company that is running a different EDR solution. A SOC analyst wants to automate the isolation of endpoints that are found to be compromised. Which of the following workflows best mitigates the risk of false positives and reduces the spread of malicious code?

  • AUsing a SOAR solution to look up entities via a TIP platform and isolate endpoints via APIs (correct answer)
  • BSetting a policy on each EDR management console to isolate all endpoints that trigger any alerts
  • CReviewing all alerts manually in the various portals and taking action to isolate them
  • DAutomating the suppression of all alerts that are not critical and sending an email asking SOC analysts to review these alerts
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Using a SOAR solution to look up entities via a TIP platform and isolate endpoints via APIs

Topic 1 Β· Question 175

While reviewing recent incident reports a security officer discovers that several employees were contacted by the same individual who impersonated a recruiter. Which of the following best describes this type of correlation?

  • ASpear-phishing campaign
  • BThreat modeling
  • CRed-team assessment
  • DAttack pattern analysis (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Attack pattern analysis This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 176

A security engineer is reviewing the following vulnerability scan report: Which of the following should the engineer prioritize for remediation?

Exhibit 1 for question 176
  • AApache HTTP Server
  • BOpenSSH (correct answer)
  • CGoogle Chrome
  • DMigration to TLS 1.3
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: OpenSSH This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 177

A company notices that cloud environment costs increased after using a new serverless solution based on API requests. Many invalid requests from unknown IPs were found, often within a short time. Which of the following solutions would most likely solve this issue, reduce cost, and improve security?

  • AUsing digital certificates for known customers and performing API authorization through those certificates
  • BDefining request rate limits and comparing new requests from unknown IPs with a list of known-malicious IPs
  • CSetting authentication processes for the API requests as well as proper rate limits according to regular usage (correct answer)
  • DOnly allowing API requests coming from regions with known customers
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Setting authentication processes for the API requests as well as proper rate limits according to regular usage This option delivers the requirement at the lowest cost.

Topic 1 Β· Question 178

A large organization deployed a generative AI platform for its global user population to use. Based on feedback received during beta testing, engineers have identified issues with user interface latency and page-loading performance for international users. The infrastructure is currently maintained within two separate data centers, which are connected using high-availability networking and load balancers. Which of the following is the best way to address the performance issues?

  • AConfiguring the application to use a CDN (correct answer)
  • BImplementing RASP to enable large language models queuing
  • CRemote journaling within a third data center
  • DTraffic shaping through the use of a SASE
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Configuring the application to use a CDN

Topic 1 Β· Question 179

A company reduced its staff 60 days ago, and applications are now starting to fail. The security analyst is investigating to determine if there is malicious intent for the application failures. The security analyst reviews the following logs: Which of the following is the most likely reason for the application failures?

Exhibit 1 for question 179
  • AThe user’s account was set as a service account (correct answer)
  • BThe user's home directory was deleted
  • CThe user does not have sudo access.
  • DThe root password has been changed
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: The user’s account was set as a service account This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 180

Source code snippets for two separate malware samples are shown below: Which of the following describes the most important observation about the two samples?

Exhibit 1 for question 180
  • ATelemetry is first buffered and then transmitted in paranoid mode
  • BThe samples were probably written by the same developer. (correct answer)
  • CBoth samples use IP connectivity for command and control
  • DSample 1 is the target agent while Sample 2 is the C2 server.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: The samples were probably written by the same developer.

Topic 1 Β· Question 181

A security analyst received a notification from a cloud service provider regarding an attack detected on a web server. The cloud service provider shared the following information about the attack: β€’ The attack came from inside the network. β€’ The attacking source IP was from the internal vulnerability scanners β€’ The scanner is not configured to target the cloud servers. Which of the following actions should the security analyst take first?

  • ACreate an allow list for the vulnerability scanner IPs in order to avoid false positives
  • BConfigure the scan policy to avoid targeting an out-of-scope host (correct answer)
  • CSet network behavior analysis rules.
  • DQuarantine the scanner sensor to perform a forensic analysis
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Configure the scan policy to avoid targeting an out-of-scope host This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 182

A company implemented a NIDS and a NIPS on the most critical environments. Since this implementation the company has been experiencing network connectivity issues. Which of the following should the security architect recommend for a new NIDS/NIPS implementation?

  • AImplementing the NIDS with a port mirror in the core switch and the NIPS in the main firewall (correct answer)
  • BImplementing the NIDS and the NIPS together with the main firewall
  • CImplementing a NIDS without a NIPS to increase the detection capability
  • DImplementing the NIDS in the bastion host and the NIPS in the branch network router
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Implementing the NIDS with a port mirror in the core switch and the NIPS in the main firewall

Explanation

A firewall enforces traffic policy by permitting or blocking connections based on configured rules. An intrusion detection system identifies and alerts on suspicious activity without normally blocking it. An intrusion prevention system detects and actively blocks malicious traffic inline. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 183 Β· Select all that apply

The material findings from a recent compliance audit indicate a company has an issue with excessive permissions. The findings show that employees changing roles or departments results in privilege creep. Which of the following solutions are the best ways to mitigate this issue? (Choose two.)

  • ASetting different access controls defined by business area
  • BImplementing a role-based access policy (correct answer)
  • CDesigning a least-needed privilege policy
  • DEstablishing a mandatory vacation policy
  • EPerforming periodic access reviews (correct answer)
  • FRequiring periodic job rotation
Reveal answer & explanation
Correct answer: B, E

The correct answer is B, E. Option B: Implementing a role-based access policy Option E: Performing periodic access reviews

Topic 1 Β· Question 184

A security analyst is reviewing a SIEM and generates the following report: Later, the incident response team notices an attack was executed on the VM001 host. Which of the following should the security analyst do to enhance the alerting process on the SIEM platform?

Exhibit 1 for question 184
  • AInclude the EDR solution on the SIEM as a new log source
  • BPerform a log correlation on the SIEM solution
  • CImprove parsing of data on the SIEM (correct answer)
  • DCreate a new rule set to detect malware
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Improve parsing of data on the SIEM

Explanation

A SIEM centralizes and correlates security events to support detection, investigation, and reporting. This option keeps traffic private / properly secured as required.

Showing questions 161–180 of 393 Β· Page 9 of 20