Latest [Dec 21, 2021] 100% Passing Guarantee - Brilliant CAS-003 Exam Questions PDF
CAS-003 Certification – Valid Exam Dumps Questions Study Guide! (Updated 574 Questions)
NEW QUESTION 77
A company is the victim of a phishing and spear-phishing campaign Users are Clicking on website links that look like common bank sites and entering their credentials accidentally A security engineer decides to use a layered defense to prevent the phishing or lessen its impact Which of the following should the security engineer implement? (Select TWO)
- A. Client certificates
- B. Spam filter
- C. Content filter
- D. Data loss prevention
- E. Log monitoring
- F. Host intrusion prevention
Answer: B,C
NEW QUESTION 78
Following a security assessment, the Chief Information Security Officer (CISO) is reviewing the results of the assessment and evaluating potential risk treatment strategies. As part of the CISO's evaluation, a judgment of potential impact based on the identified risk is performed. To prioritize response actions, the CISO uses past experience to take into account the exposure factor as well as the external accessibility of the weakness identified.
Which of the following is the CISO performing?
- A. Documentation of lessons learned
- B. Quantitative risk assessment
- C. Threat modeling
- D. Qualitative assessment of risk
- E. Business impact scoring
Answer: D
NEW QUESTION 79
A security administrator was doing a packet capture and noticed a system communicating with an unauthorized address within the 2001::/32 prefix. The network administrator confirms there is no IPv6 routing into or out of the network.
Which of the following is the BEST course of action?
- A. Disable the switch port and block the 2001::/32 traffic at the firewall
- B. Locate and remove the unauthorized 6to4 relay from the network
- C. Remove the system from the network and disable IPv6 at the router
- D. Investigate the network traffic and block UDP port 3544 at the firewall
Answer: D
Explanation:
The 2001::/32 prefix is used for Teredo tunneling.
Teredo is a transition technology that gives full IPv6 connectivity for IPv6-capable hosts that are on the IPv4 Internet but have no native connection to an IPv6 network. Unlike similar protocols, it can perform its function even from behind network address translation (NAT) devices such as home routers.
Teredo provides IPv6 (Internet Protocol version 6) connectivity by encapsulating IPv6 datagram packets within IPv4 User Datagram Protocol (UDP) packets. Teredo routes these datagrams on the IPv4 Internet and through NAT devices. Teredo nodes elsewhere on the IPv6 network (called Teredo relays) receive the packets, decapsulate them, and pass them on. The Teredo server listens on UDP port 3544.
Teredo clients are assigned an IPv6 address that starts with the Teredo prefix (2001::/32).
In this question, the BEST course of action would be to block UDP port 3544 at the firewall. This will block the unauthorized communication. You can then investigate the traffic within the network.
Incorrect Answers:
B: Disabling IPv6 at the router will not help if the IPv6 traffic is encapsulated in IPv4 frames using Teredo. The question also states that there is no IPv6 routing into or out of the network.
C: 6to4 relays work in a similar way to Teredo. However, the addresses used by 6to4 relays start with 2002:: whereas Teredo addresses start with 2001. Therefore, a 6to4 relay is not being used in this question so this answer is incorrect.
D: This question is asking for the BEST solution. Disabling the switch port would take the system connected to it offline and blocking traffic destined for 2001::/32 at the firewall would prevent inbound Teredo communications (if you block the traffic on the inbound interface). However, blocking port UDP 3544 would suffice and investigating the traffic is always a better solution than just disconnecting a system from the network.
References:
https://en.wikipedia.org/wiki/Teredo_tunneling
NEW QUESTION 80
A security administrator wants to deploy a dedicated storage solution which is inexpensive, can natively integrate with AD, allows files to be selectively encrypted and is suitable for a small number of users at a satellite office. Which of the following would BEST meet the requirement?
- A. Virtual SAN
- B. Virtual storage
- C. SAN
- D. NAS
Answer: D
Explanation:
A NAS is an inexpensive storage solution suitable for small offices. Individual files can be encrypted by using the EFS (Encrypted File System) functionality provided by the NTFS file system.
NAS typically uses a common Ethernet network and can provide storage services to any authorized devices on that network.
Two primary NAS protocols are used in most environments. The choice of protocol depends largely on the type of computer or server connecting to the storage. Network File System (NFS) protocol usually used by servers to access storage in a NAS environment. Common Internet File System (CIFS), also sometimes called Server Message Block (SMB), is usually used for desktops, especially those running Microsoft Windows. Unlike DAS and SAN, NAS is a file-level storage technology. This means the NAS appliance maintains and controls the files, folder structures, permission, and attributes of the data it holds. A typical NAS deployment integrates the NAS appliance with a user database, such as Active Directory, so file permissions can be assigned based on established users and groups. With Active Directory integration, most Windows New Technology File System (NTFS) permissions can be set on the files contained on a NAS device.
NEW QUESTION 81
A technician is reviewing the following log:
Which of the following tools should the organization implement to reduce the highest risk identified in this log?
- A. NGFW
- B. NIPS
- C. DLP
- D. SIEM
Answer: C
NEW QUESTION 82
A medical device company is implementing a new COTS antivirus solution in its manufacturing plant. All
validated machines and instruments must be retested for interoperability with the new software.
Which of the following would BEST ensure the software and instruments are working as designed?
- A. Peer review
- B. Change control documentation
- C. System design documentation
- D. User acceptance testing
- E. Static code analysis testing
Answer: C
NEW QUESTION 83
A company is migrating systems from an on-premises facility to a third-party managed datacenter. For continuity of operations and business agility, remote access to all hardware platforms must be available at all times. Access controls need to be very robust and provide an audit trail. Which of the following security controls will meet the company's objectives? (Select two.)
- A. Application logs are hashed cryptographically and sent to the SIEM
- B. Access to hardware platforms is restricted to the systems administrator's IP address
- C. Access is limited to interactive logins on the VDi
- D. Integrated platform management interfaces are configured to allow access only via SSH
- E. Access is captured in event logs that include source address, time stamp, and outcome
- F. The IP addresses of server management interfaces are located within the company's extranet
Answer: C,E
NEW QUESTION 84
An investigator wants to collect the most volatile data first in an incident to preserve the data that runs the highest risk of being lost. After memory, which of the following BEST represents the remaining order of volatility that the investigator should follow?
- A. System processes, network processes, file system information, swap files and raw disk blocks.
- B. Raw disk blocks, swap files, network processes, system processes, and file system information.
- C. Raw disk blocks, network processes, system processes, swap files and file system information.
- D. File system information, swap files, network processes, system processes and raw disk blocks.
Answer: A
Explanation:
The order in which you should collect evidence is referred to as the Order of volatility. Generally, evidence should be collected from the most volatile to the least volatile. The order of volatility from most volatile to least volatile is as follows:
Data in RAM, including CPU cache and recently used data and applications Data in RAM, including system and network processes Swap files (also known as paging files) stored on local disk drives Data stored on local disk drives Logs stored on remote systems Archive media
NEW QUESTION 85
A network administrator is concerned about a particular server that is attacked occasionally from hosts on the Internet. The server is not critical; however, the attacks impact the rest of the network. While the company's current ISP is cost effective, the ISP is slow to respond to reported issues. The administrator needs to be able to mitigate the effects of an attack immediately without opening a trouble ticket with the ISP. The ISP is willing to accept a very small network route advertised with a particular BGP community string. Which of the following is the BESRT way for the administrator to mitigate the effects of these attacks?
- A. Advertise a /32 route to the ISP to initiate a remotely triggered black hole, which will discard traffic destined to the problem server at the upstream provider.
- B. Use the route protection offered by the ISP to accept only BGP routes from trusted hosts on the Internet, which will discard traffic from attacking hosts.
- C. Work with the ISP and subscribe to an IPS filter that can recognize the attack patterns of the attacking hosts, and block those hosts at the local IPS device.
- D. Add a redundant connection to a second local ISP, so a redundant connection is available for use if the server is being attacked on one connection.
Answer: A
NEW QUESTION 86
After the departure of a developer under unpleasant circumstances, the company is concerned about the security of the software to which the developer has access. Which of the following is the BEST way to ensure security of the code following the incident?
- A. Hirean externalred temtoconductblackboxtesting
- B. Performregressiontesting and search forsuspiciouscode
- C. Conductapeerreviewand crossreferencetheSRTM
- D. Performwhite-box testingon allimpacted finishedproducts
Answer: A
NEW QUESTION 87
An external red team member conducts a penetration test, attempting to gain physical access to a large organization's server room in a branch office. During reconnaissance, the red team member sees a clearly marked door to the server room, located next to the lobby, with a tumbler lock.
Which of the following is BEST for the red team member to bring on site to open the locked door as quickly as possible without causing significant damage?
- A. Screwdriver set
- B. RFID duplicator
- C. Rake picking
- D. Bump key
Answer: D
NEW QUESTION 88
Legal counsel has notified the information security manager of a legal matter that will require the preservation of electronic records for 2000 sales force employees. Source records will be email, PC, network shares, and applications.
After all restrictions have been lifted, which of the following should the information manager review?
- A. Scope statement
- B. Data retention policy
- C. Legal hold
- D. Chain of custody
Answer: B
NEW QUESTION 89
A security manager is looking into the following vendor proposal for a cloud-based SIEM solution. The intention is that the cost of the SIEM solution will be justified by having reduced the number of incidents and therefore saving on the amount spent investigating incidents.
Proposal:
External cloud-based software as a service subscription costing $5,000 per month. Expected to reduce the number of current incidents per annum by 50%.
The company currently has ten security incidents per annum at an average cost of $10,000 per incident. Which of the following is the ROI for this proposal after three years?
- A. $120,000
- B. -$30,000
- C. $180,000
- D. $150,000
Answer: B
Explanation:
Return on investment = Net profit / Investment
where: Net profit = gross profit - expenses.
or
Return on investment = (gain from investment - cost of investment) / cost of investment Subscriptions = 5,000 x 12 = 60,000 per annum
10 incidents @ 10,000 = 100.000 per annum reduce by 50% = 50,000 per annum Thus the rate of Return is -10,000 per annum and that makes for -$30,000 after three years.
References:
http://www.financeformulas.net/Return_on_Investment.html
NEW QUESTION 90
A security engineer is assessing a new IoT product. The product interfaces with the ODBII port of a vehicle and uses a Bluetooth connection to relay data to an onboard data logger located in the vehicle. The data logger can only transfer data over a custom USB cable. The engineer suspects a relay attack is possible against the cryptographic implementation used to secure messages between segments of the system. Which of the following tools should the engineer use to confirm the analysis?
- A. Log analysis and reduction tools
- B. Binary decompiler
- C. Network-based fuzzer
- D. Wireless protocol analyzer
Answer: D
NEW QUESTION 91
An administrator wants to install a patch to an application.
INSTRUCTIONS
Given the scenario, download, verify, and install the patch in the most secure manner.
The last install that is completed will be the final submission.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.






Answer:
Explanation:
In this case the second link should be used (This may vary in actual exam). The first link showed the following error so it should not be used.
Also, Two of the link choices used HTTP and not HTTPS as shown when hovering over the links as shown:
Since we need to do this in the most secure manner possible, they should not be used.Finally, the second link was used and the MD5 utility of MD5sum should be used on the install.exe file as shown. Make sure that the hash matches.
Finally, type in install.exe to install it and make sure there are no signature verification errors.
NEW QUESTION 92
An engineer wants to assess the OS security configurations on a company's servers. The engineer has downloaded some files to orchestrate configuration checks When the engineer opens a file in a text editor, the following excerpt appears:
Which of the following capabilities would a configuration compliance checker need to support to interpret this file?
- A. Nessus
- B. WSDL
- C. Swagger file
- D. Netcat
- E. SCAP
Answer: E
NEW QUESTION 93
......
What is CompTIA CASP+ certification for certified specialists?
Reputable global organizations demand professional-level skills and are willing to employ those who demonstrate their expertise in the field of cybersecurity. This includes the US Army, Verizon, Northrop Grumman, and DELL. This is advantageous because the CompTIA CASP+ certification is vendor-neutral, which means that you can work across technologies irrespective of the vendor. Some job titles related to this certificate are a Security Architect, a Technical Lead Analyst, an App Security Engineer, and a Security Engineer. Based on the latest PayScale report, a certified specialist can make about $88,000 annually.
CAS-003 are Available for Instant Access: https://www.exam-killer.com/CAS-003-valid-questions.html
CAS-003 Dumps 2021 - New CompTIA CAS-003 Exam Questions: https://drive.google.com/open?id=1pqzjc-WEwRFFbiqkMfEmpiYWEDFcSu7w

