CompTIA CAS-002 - CompTIA Advanced Security Practitioner (CASP) Exam

Question #11 (Topic: Topic 1)
A government agency considers confidentiality to be of utmost importance and availability
issues to be of least importance. Knowing this, which of the following correctly orders
various vulnerabilities in the order of MOST important to LEAST important?
A. Insecure direct object references, CSRF, Smurf B. Privilege escalation, Application DoS, Buffer overflow C. SQL injection, Resource exhaustion, Privilege escalation D. CSRF, Fault injection, Memory leaks
Answer: A
Question #12 (Topic: Topic 1)
Due to compliance regulations, a company requires a yearly penetration test. The Chief
Information Security Officer (CISO) has asked that it be done under a black box
methodology.
Which of the following would be the advantage of conducting this kind of penetration test?
A. The risk of unplanned server outages is reduced. B. Using documentation provided to them, the pen-test organization can quickly determine areas to focus on. C. The results will show an in-depth view of the network and should help pin-point areas of internal weakness. D. The results should reflect what attackers may be able to learn about the company.
Answer: D
Question #13 (Topic: Topic 1)
There have been some failures of the companys internal facing website. A security
engineer has found the WAF to be the root cause of the failures. System logs show that the
WAF has been unavailable for 14 hours over the past month, in four separate situations.
One of these situations was a two hour scheduled maintenance time, aimed at improving
the stability of the WAF. Using the MTTR based on the last months performance figures,
which of the following calculations is the percentage of uptime assuming there were 722
hours in the month?
A. 92.24 percent B. 98.06 percent C. 98.34 percent D. 99.72 percent
Answer: C
Question #14 (Topic: Topic 1)
A security manager for a service provider has approved two vendors for connections to the
service provider backbone. One vendor will be providing authentication services for its
payment card service, and the other vendor will be providing maintenance to the service
provider infrastructure sites. Which of the following business agreements is MOST relevant
to the vendors and service providers relationship?
A. Memorandum of Agreement B. Interconnection Security Agreement C. Non-Disclosure Agreement D. Operating Level Agreement
Answer: B
Question #15 (Topic: Topic 1)
A security administrator wants to prevent sensitive data residing on corporate laptops and
desktops from leaking outside of the corporate network. The company has already
implemented full-disk encryption and has disabled all peripheral devices on its desktops
and laptops. Which of the following additional controls MUST be implemented to minimize
the risk of data leakage? (Select TWO).
A. A full-system backup should be implemented to a third-party provider with strong encryption for data in transit. B. A DLP gateway should be installed at the company border. C. Strong authentication should be implemented via external biometric devices. D. Full-tunnel VPN should be required for all network communication. E. Full-drive file hashing should be implemented with hashes stored on separate storage. F. Split-tunnel VPN should be enforced when transferring sensitive data.
Answer: B,D
Download Exam
Page: 3 / 107
Total 532 questions