Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA CompTIA CASP CAS-005 Questions and answers with CertsForce

Viewing page 6 out of 11 pages
Viewing questions 51-60 out of questions
Questions # 51:

An incident response analyst finds the following content inside of a log file that was collected from a compromised server:

.2308464678 ... whoami ..... su2032829%72%322/// ...... /etc/passwd .... 2087031731467478432 ...

$6490/90/./ .. < XML ?.. .... nty.

Which of the following is the best action to prevent future compromise?

Options:

A.

Blocking the processing of external files by forwarding them to another server for processing


B.

Implementing an allow list for all text boxes throughout the web application


C.

Filtering inserted characters for all user inputs and allowing only ASCII characters


D.

Improving file-parsing capabilities to stop external entities from executing commands


Expert Solution
Questions # 52:

A malicious actor exploited firmware vulnerabilities and used rootkits in an attack on an organization. After the organization recovered from the incident, an engineer needs to recommend a solution that reduces the likelihood of the same type of attack in the future. Which of the following is the most relevant solution?

Options:

A.

Enabling software integrity checks


B.

Installing self-encrypting drives


C.

Implementing measured boot


D.

Configuring host-based encryption


Expert Solution
Questions # 53:

You are a security analyst tasked with interpreting an Nmap scan output from company’s privileged network.

The company’s hardening guidelines indicate the following:

There should be one primary server or service per device.

Only default ports should be used.

Non-secure protocols should be disabled.

INSTRUCTIONS

Using the Nmap output, identify the devices on the network and their roles, and any open ports that should be closed.

For each device found by Nmap, add a device entry to the Devices Discovered list, with the following information:

The IP address of the device

The primary server or service of the device (Note that each IP should by associated with one service/port only)

The protocol(s) that should be disabled based on the hardening guidelines (Note that multiple ports may need to be closed to comply with the hardening guidelines)

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Question # 53

Question # 53


Expert Solution
Questions # 54:

A company plans to deploy a new online application that provides video training for its customers. As part of the design, the application must be:

• Fast for all users

• Available for users worldwide

• Protected against attacks

Which of the following are the best components the company should use to meet these requirements? (Select two).

Options:

A.

WAF


B.

IPS


C.

CDN


D.

SASE


E.

VPN


F.

CASB


Expert Solution
Questions # 55:

The ISAC for the retail industry recently released a report regarding social engineering tactics in which small groups create distractions for employees while other malicious individuals install advanced card skimmers on the payment systems. The Chief Information Security Officer (CISO) thinks that security awareness training, technical control implementations, and governance already in place is adequate to protect from this threat. The board would like to test these controls. Which of the following should the CISO recommend?

Options:

A.

Dark web monitoring


B.

Adversary emulation engagement


C.

Supply chain risk consultation


D.

Tabletop exercises


Expert Solution
Questions # 56:

A development team must create a website to share indicators of compromise. The team wants to use APIs between industry peers to aid in configuring SIEM and SOAR. The team needs to create a free tier of service, and the senior developer insists on configuring rate limiting. Which of the following best describes the senior developer ' s reasoning?

Options:

A.

To prevent password-spraying attacks on the services hosting the API


B.

To limit the likelihood of resource exhaustion occurring on the API server


C.

To address concerns the team has about API bandwidth utilization


D.

To reduce attack surface exposure of the API endpoints connecting peers


Expert Solution
Questions # 57:

A security analyst isreviewing the following event timeline from an COR solution:

Question # 57

Which of the following most likely has occurred and needs to be fixed?

Options:

A.

The Dl P has failed to block malicious exfiltration and data tagging is not being utilized property


B.

An EDRbypass was utilized by a threat actor and updates must be installed by the administrator.


C.

A logic law has introduced a TOCTOU vulnerability and must be addressed by the COR vendor


D.

A potential insider threat is being investigated and will be addressed by the senior management team.


Expert Solution
Questions # 58:

An organization is developing a disaster recovery plan that requires data to be backed up and available at a moment ' s notice. Which of the following should the organization consider first to address this requirement?

Options:

A.

Implement a change management plan to ensure systems are using the appropriate versions.


B.

Hire additional on-call staff to be deployed if an event occurs.


C.

Design an appropriate warm site for business continuity.


D.

Identify critical business processes and determine associated software and hardware requirements.


Expert Solution
Questions # 59:

Users are experiencing a variety of issueswhen trying to access corporate resources examples include

• Connectivity issues between local computers and file servers within branch offices

• Inability to download corporate applications on mobile endpoints wtiilc working remotely

• Certificate errors when accessing internal web applications

Which of the following actions are the most relevant when troubleshooting the reported issues? (Select two).

Options:

A.

Review VPN throughput


B.

Check IPS rules


C.

Restore static content on lite CDN.


D.

Enable secure authentication using NAC


E.

Implement advanced WAF rules.


F.

Validate MDM asset compliance


Expert Solution
Questions # 60:

A company recentlyexperienced aransomware attack. Although the company performssystems and data backupon a schedule that aligns with itsRPO (Recovery Point Objective) requirements, thebackup administratorcould not recovercritical systems and datafrom its offline backups to meet the RPO. Eventually, the systems and data were restored with information that wassix months outside of RPO requirements.

Which of the following actions should the company take to reduce the risk of a similar attack?

Options:

A.

Encrypt and label the backup tapes with the appropriate retention schedule before they are sent to the off-site location.


B.

Implement a business continuity process that includes reverting manual business processes.


C.

Perform regular disaster recovery testing of IT and non-IT systems and processes.


D.

Carry out a tabletop exercise to update and verify the RACI matrix with IT and critical business functions.


Expert Solution
Viewing page 6 out of 11 pages
Viewing questions 51-60 out of questions