[Q322-Q340] Latest CompTIA CAS-003 First Attempt, Exam real Dumps Updated [Sep-2021]

Share

Latest CompTIA CAS-003 First Attempt, Exam real Dumps Updated [Sep-2021]

Get the superior quality CAS-003 Dumps Questions from ExamsLabs. Nobody can stop you from getting to your dreams now. Your bright future is just a click away!

NEW QUESTION 322
The Information Security Officer (ISO) believes that the company has been targeted by cybercriminals and it is under a cyber attack. Internal services that are normally available to the public via the Internet are inaccessible, and employees in the office are unable to browse the Internet. The senior security engineer starts by reviewing the bandwidth at the border router, and notices that the incoming bandwidth on the router's external interface is maxed out. The security engineer then inspects the following piece of log to try and determine the reason for the downtime, focusing on the company's external router's IP which is
128.20.176.19:
11:16:22.110343 IP 90.237.31.27.19 > 128.20.176.19.19: UDP, length 1400
11:16:22.110351 IP 23.27.112.200.19 > 128.20.176.19.19: UDP, length 1400
11:16:22.110358 IP 192.200.132.213.19 > 128.20.176.19.19: UDP, length 1400
11:16:22.110402 IP 70.192.2.55.19 > 128.20.176.19.19: UDP, length 1400
11:16:22.110406 IP 112.201.7.39.19 > 128.20.176.19.19: UDP, length 1400 Which of the following describes the findings the senior security engineer should report to the ISO and the BEST solution for service restoration?

  • A. After the senior engineer used a mirror port to capture the ongoing amplification attack, a BGP sinkhole should be configured to drop traffic at the source networks.
  • B. After the senior engineer used the above IPS logs to detect the ongoing DDOS attack, an IPS filter should be enabled to block the attack and restore communication.
  • C. After the senior engineer used a network analyzer to identify an active Fraggle attack, the company's ISP should be contacted and instructed to block the malicious packets.
  • D. After the senior engineer used a packet capture to identify an active Smurf attack, an ACL should be placed on the company's external router to block incoming UDP port 19 traffic.

Answer: C

Explanation:
Explanation
The exhibit displays logs that are indicative of an active fraggle attack. A Fraggle attack is similar to a smurf attack in that it is a denial of service attack, but the difference is that a fraggle attack makes use of ICMP and UDP ports 7 and 19. Thus when the senior engineer uses a network analyzer to identify the attack he should contact the company's ISP to block those malicious packets.

 

NEW QUESTION 323
A security administrator wants to calculate the ROI of a security design which includes the purchase of new equipment. The equipment costs $50,000 and it will take 50 hours to install and configure the equipment. The administrator plans to hire a contractor at a rate of $100/hour to do the installation. Given that the new design and equipment will allow the company to increase revenue and make an additional $100,000 on the first year, which of the following is the ROI expressed as a percentage for the first year?

  • A. -45 percent
  • B. 5.5 percent
  • C. 82 percent
  • D. 45 percent

Answer: C

Explanation:
Return on investment = Net profit / Investment
where: Net profit = gross profit - expenses
investment = stock + market outstanding[when defined as?] + claims
or
Return on investment = (gain from investment - cost of investment) / cost of investment Thus (100 000 - 55 000)/50 000 = 0,82 = 82 % References:
Gregg, Michael, and Billy Haines, CASP CompTIA Advanced Security Practitioner Study Guide, John Wiley & Sons, Indianapolis, 2012, p. 337
http://www.financeformulas.net/Return_on_Investment.html

 

NEW QUESTION 324
A security architect has been assigned to a new digital transformation program. The objectives are to
provide better capabilities to customers and reduce costs. The program has highlighted the following
requirements:
1. Long-lived sessions are required, as users do not log in very often.
2. The solution has multiple SPs, which include mobile and web applications.
3. A centralized IdP is utilized for all customer digital channels.
4. The applications provide different functionality types such as forums and customer portals.
5. The user experience needs to be the same across both mobile and web-based applications.
Which of the following would BEST improve security while meeting these requirements?

  • A. Create-based authentication to IdP, securely store access tokens, and implement secure push
    notifications.
  • B. Username and password authentication to SP, securely store Java web tokens, and implement SMS
    OTPs.
  • C. Username and password authentication to IdP, securely store refresh tokens, and implement context-
    aware authentication.
  • D. Social login to IdP, securely store the session cookies, and implement one-time passwords sent to the
    mobile device

Answer: D

 

NEW QUESTION 325
An application present on the majority of an organization's 1,000 systems is vulnerable to a buffer overflow attack. Which of the following is the MOST comprehensive way to resolve the issue?

  • A. Deploy custom NIPS signatures to detect and block the attacks.
  • B. Deploy custom HIPS signatures to detect and block the attacks.
  • C. Run the application in terminal services to reduce the threat landscape.
  • D. Validate and deploy the appropriate patch.

Answer: D

Explanation:
Explanation
If an application has a known issue (such as susceptibility to buffer overflow attacks) and a patch is released to resolve the specific issue, then the best solution is always to deploy the patch.
A buffer overflow occurs when a program or process tries to store more data in a buffer (temporary data storage area) than it was intended to hold. Since buffers are created to contain a finite amount of data, the extra information - which has to go somewhere - can overflow into adjacent buffers, corrupting or overwriting the valid data held in them. Although it may occur accidentally through programming error, buffer overflow is an increasingly common type of security attack on data integrity. In buffer overflow attacks, the extra data may contain codes designed to trigger specific actions, in effect sending new instructions to the attacked computer that could, for example, damage the user's files, change data, or disclose confidential information. Buffer overflow attacks are said to have arisen because the C programming language supplied the framework, and poor programming practices supplied the vulnerability.

 

NEW QUESTION 326
A company has implemented data retention policies and storage quotas in response to their legal department's requests and the SAN administrator's recommendation.
The retention policy states all email data older than 90 days should be eliminated.
As there are no technical controls in place, users have been instructed to stick to a storage quota of 500Mb of network storage and 200Mb of email storage.
After being presented with an e-discovery request from an opposing legal council, the security administrator discovers that the user in the suit has 1Tb of files and 300Mb of email spanning over two years.
Which of the following should the security administrator provide to opposing council?

  • A. Delete files and email exceeding policy thresholds and turn over the remaining files and email.
  • B. Provide the 1Tb of files on the network and the 300Mb of email files regardless of age.
  • C. Delete email over the policy threshold and hand over the remaining emails and all of the files.
  • D. Provide the first 200Mb of e-mail and the first 500Mb of files as per policy.

Answer: B

 

NEW QUESTION 327
The helpdesk is receiving multiple calls about slow and intermittent Internet access from the finance department. The following information is compiled:
Caller 1, IP 172.16.35.217, NETMASK 255.255.254.0
Caller 2, IP 172.16.35.53, NETMASK 255.255.254.0
Caller 3, IP 172.16.35.173, NETMASK 255.255.254.0
All callers are connected to the same switch and are routed by a router with five built-in interfaces. The upstream router interface's MAC is 00-01-42-32-ab-1a
A packet capture shows the following:
09:05:15.934840 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)
09:06:16.124850 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)
09:07:25.439811 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)
09:08:10.937590 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2305, seq 1, length 65534
09:08:10.937591 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2306, seq 2, length 65534
09:08:10.937592 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2307, seq 3, length 65534
Which of the following is occurring on the network?

  • A. A denial of service attack is targeting at the router.
  • B. An ARP flood attack is targeting at the router.
  • C. A man-in-the-middle attack is underway on the network.
  • D. The default gateway is being spoofed on the network.

Answer: A

Explanation:
The above packet capture shows an attack where the attacker is busy consuming your resources (in this case the router) and preventing normal use. This is thus a Denial Of Service Attack.
Incorrect Answers:
A: A man-in-the-middle attack is when an attacker intercepts and perhaps changes the data that is transmitted between two users. The packet capture is not indicative of a man-in-the-middle attack.
B: With an ARP flood attack thousands of spoofed data packets with different physical addresses are sent to a device. This is not the case here.
C: A gateway being spoofed show up as any random number that the attacker feels like listing as the caller. This is not what is exhibited in this case.
References:
Gregg, Michael, and Billy Haines, CASP CompTIA Advanced Security Practitioner Study Guide, John Wiley & Sons, Indianapolis, 2012, p. 286

 

NEW QUESTION 328
The network administrator at an enterprise reported a large data leak. One compromised server was used to aggregate data from several critical application servers and send it out to the Internet using HTTPS. Upon investigation, there have been no user logins over the previous week and the endpoint protection software is not reporting any issues. Which of the following BEST provides insight into where the compromised server collected the information?

  • A. Review the flow data against each server's baseline communications profile.
  • B. Correlate data loss prevention logs for anomalous communications from the server.
  • C. Configure the server logs to collect unusual activity including failed logins and restarted services.
  • D. Setup a packet capture on the firewall to collect all of the server communications.

Answer: A

Explanation:
Explanation
Network logging tools such as Syslog, DNS, NetFlow, behavior analytics, IP reputation, honeypots, and DLP solutions provide visibility into the entire infrastructure. This visibility is important because signature-based systems are no longer sufficient for identifying the advanced attacker that relies heavily on custom malware and zero-day exploits. Having knowledge of each host's communications, protocols, and traffic volumes as well as the content of the data in question is key to identifying zero-day and APT (advance persistent threat) malware and agents. Data intelligence allows forensic analysis to identify anomalous or suspicious communications by comparing suspected traffic patterns against normal data communication behavioral baselines. Automated network intelligence and next-generation live forensics provide insight into network events and rely on analytical decisions based on known vs. unknown behavior taking place within a corporate network.

 

NEW QUESTION 329
An analyst connects to a company web conference hosted on
www.webconference.com/meetingID#01234 and observes that numerous guests have been allowed to join, without providing identifying information. The topics covered during the web conference are considered proprietary to the company. Which of the following security concerns does the analyst present to management?

  • A. Meeting owners could sponsor guest access if they have passed a background check.
  • B. Guest users could present a risk to the integrity of the company's information.
  • C. Unauthenticated users could present a risk to the confidentiality of the company's information.
  • D. Authenticated users could sponsor guest access that was previously approved by management.

Answer: C

Explanation:
The issue at stake in this question is confidentiality of information. Topics covered during the web conference are considered proprietary and should remain confidential, which means it should not be shared with unauthorized users.

 

NEW QUESTION 330
The helpdesk is receiving multiple calls about slow and intermittent Internet access from the finance department. The following information is compiled:
Caller 1, IP 172.16.35.217, NETMASK 255.255.254.0
Caller 2, IP 172.16.35.53, NETMASK 255.255.254.0
Caller 3, IP 172.16.35.173, NETMASK 255.255.254.0
All callers are connected to the same switch and are routed by a router with five built-in interfaces. The upstream router interface's MAC is 00-01-42-32-ab-1a A packet capture shows the following:
09:05:15.934840 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)
09:06:16.124850 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)
09:07:25.439811 arp reply 172.16.34.1 is-at 00:01:42:32:ab:1a (00:01:42:32:ab:1a)
09:08:10.937590 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2305, seq 1, length 65534
09:08:10.937591 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2306, seq 2, length 65534
09:08:10.937592 IP 172.16.35.1 > 172.16.35.255: ICMP echo request, id 2307, seq 3, length 65534 Which of the following is occurring on the network?

  • A. A denial of service attack is targeting at the router.
  • B. An ARP flood attack is targeting at the router.
  • C. A man-in-the-middle attack is underway on the network.
  • D. The default gateway is being spoofed on the network.

Answer: A

Explanation:
Explanation
The above packet capture shows an attack where the attacker is busy consuming your resources (in this case the router) and preventing normal use. This is thus a Denial Of Service Attack.

 

NEW QUESTION 331
A company's security policy states any remote connections must be validated using two forms of network- based authentication. It also states local administrative accounts should not be used for any remote access.
PKI currently is not configured within the network. RSA tokens have been provided to all employees, as well as a mobile application that can be used for 2FA authentication. A new NGFW has been installed within the network to provide security for external connections, and the company has decided to use it for VPN connections as well. Which of the following should be configured? (Choose two.)

  • A. Local user database
  • B. LDAP
  • C. Certificate-based authentication
  • D. RADIUS
  • E. 802.1X
  • F. TACACS+

Answer: B,D

 

NEW QUESTION 332
The Chief Information Security Officer (CISO) for an organization wants to develop custom IDS rulesets faster, prior to new rules being released by IDS vendors. Which of the following BEST meets this objective?

  • A. Encourage cybersecurity analysts to review open-source intelligence products and threat database to generate new IDS rules based on those sources
  • B. Use annual hacking conventions to document the latest attacks and threats, and then develop IDS rules to counter those threats
  • C. Leverage the latest TCP- and UDP-related RFCs to arm sensors and IDSs with appropriate heuristics for anomaly detection
  • D. Identify a third-party source for IDS rules and change the configuration on the applicable IDSs to pull in the new rulesets

Answer: A

Explanation:
Section: (none)

 

NEW QUESTION 333
An organization enables BYOD but wants to allow users to access the corporate email, calendar, and contacts from their devices. The data associated with the user's accounts is sensitive, and therefore, the organization wants to comply with the following requirements:
Active full-device encryption
Enabled remote-device wipe
Blocking unsigned applications
Containerization of email, calendar, and contacts
Which of the following technical controls would BEST protect the data from attack or loss and meet the above requirements?

  • A. Install a mobile antivirus application.
  • B. Configure and monitor devices with an MDM.
  • C. Enforce device encryption and activate MAM.
  • D. Require frequent password changes and disable NFC.

Answer: B

 

NEW QUESTION 334
Several recent ransomware outbreaks at a company have cost a significant amount of lost revenue. The security team needs to find a technical control mechanism that will meet the following requirements and aid in preventing these outbreaks:
- Stop malicious software that does not match a signature
- Report on instances of suspicious behavior
- Protect from previously unknown threats
- Augment existing security capabilities
Which of the following tools would BEST meet these requirements?

  • A. HIPS
  • B. Host-based firewall
  • C. EDR
  • D. Patch management

Answer: C

Explanation:
https://www.crowdstrike.com/epp-101/what-is-endpoint-detection-and-response-edr/

 

NEW QUESTION 335
An engineer needs to provide access to company resources for several offshore contractors. The contractors require:
* Access to a number of applications, including internal websites
* Access to database data and the ability to manipulate it
* The ability to log into Linux and Windows servers remotely
Which of the following remote access technologies are the BEST choices to provide all of this access securely? (Choose two.)

  • A. VLAN
  • B. VPN
  • C. VTC
  • D. VRRP
  • E. VDI
  • F. Telnet

Answer: B,E

 

NEW QUESTION 336
A web services company is planning a one-time high-profile event to be hosted on the corporate website. An outage, due to an attack, would be publicly embarrassing, so Joe, the Chief Executive Officer (CEO), has requested that his security engineers put temporary preventive controls in place. Which of the following would MOST appropriately address Joe's concerns?

  • A. Contract and configure scrubbing services with third-party DDoS mitigation providers.
  • B. Configure an intrusion prevention system that blocks IPs after detecting too many incomplete sessions.
  • C. Purchase additional bandwidth from the company's Internet service provider.
  • D. Ensure web services hosting the event use TCP cookies and deny_hosts.

Answer: A

Explanation:
Scrubbing is an excellent way of dealing with this type of situation where the company wants to stay connected no matter what during the one-time high profile event. It involves deploying a multi-layered security approach backed by extensive threat research to defend against a variety of attacks with a guarantee of always-on.

 

NEW QUESTION 337
A SaaS-based email service provider often receives reports from legitimate customers that their IP netblocks are on blacklists and they cannot send email. The SaaS has confirmed that affected customers typically have IP addresses within broader network ranges and some abusive customers within the same IP ranges may have performed spam campaigns. Which of the following actions should the SaaS provider perform to minimize legitimate customer impact?

  • A. Work with the legal department and threaten legal action against the blacklist operator if the netblocks are not removed because this is affecting legitimate traffic
  • B. Inform the customer that the service provider does not have any control over third-party blacklist entries.
    The customer should reach out to the blacklist operator directly
  • C. Establish relationship with a blacklist operators so broad entries can be replaced with more granular entries and incorrect entries can be quickly pruned
  • D. Perform a takedown of any customer accounts that have entries on email blacklists because this is a strong indicator of hostile behavior

Answer: C

 

NEW QUESTION 338
A technician is validating compliance with organizational policies. The user and machine accounts in the
AD are not set to expire, which is non-compliant. Which of the following network tools would provide this
type of information?

  • A. IDS appliance
  • B. HTTP interceptor
  • C. SIEM server
  • D. SCAP scanner

Answer: A

 

NEW QUESTION 339
While investigating suspicious activity on a server, a security administrator runs the following report:

In addition, the administrator notices changes to the /etc/shadow file that were not listed in the report. Which of the following BEST describe this scenario? (Choose two.)

  • A. An attacker compromised the server and may have installed a rootkit to always generate valid MD5 hashes to hide the changes to the /etc/shadow file
  • B. An attacker compromised the server and may have also compromised the file integrity database to hide the changes to the /etc/shadow file
  • C. An attacker compromised the server and may have used MD5 collision hashes to generate valid passwords, allowing further access to administrator accounts on the server
  • D. An attacker compromised the server and may have used a collision hash in the MD5 algorithm to hide the changes to the /etc/shadow file
  • E. An attacker compromised the server and may have used SELinux mandatory access controls to hide the changes to the /etc/shadow file

Answer: C

 

NEW QUESTION 340
......

Guaranteed Success with Valid CompTIA CAS-003 Dumps: https://www.examslabs.com/CompTIA/CASP-Recertification/best-CAS-003-exam-dumps.html