CompTIA Advanced Security Practitioner (CASP+) - CAS-004 Exam Practice Test

A company processes data subject to NDAs with partners that define the processing and storage constraints for the covered data. The agreements currently do not permit moving the covered data to the cloud, and the company would like to renegotiate the terms of the agreements.
Which of the following would MOST likely help the company gain consensus to move the data to the cloud?
Correct Answer: B
A company is rewriting a vulnerable application and adding the inprotect () system call in multiple parts of the application's code that was being leveraged by a recent exploitation tool.
Which of the following should be enabled to ensure the application can leverage the new system call against similar attacks in the future?
Correct Answer: C
A networking team asked a security administrator to enable Flash on its web browser. The networking team explained that an important legacy embedded system gathers SNMP information from various devices. The system can only be managed through a web browser running Flash. The embedded system will be replaced within the year but is still critical at the moment.
Which of the following should the security administrator do to mitigate the risk?
Correct Answer: C
A cybersecurity analyst discovered a private key that could have been exposed.
Which of the following is the BEST way for the analyst to determine if the key has been compromised?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A security analyst is trying to identify the source of a recent data loss incident. The analyst has reviewed all the for the time surrounding the identified all the assets on the network at the timeof the data loss. The analyst suspects the key to finding the source was obfuscated in an application. Which of the following tools should the analyst use NEXT?
Correct Answer: B
A Chief Information Officer is considering migrating all company data to the cloud to save money on expensive SAN storage.
Which of the following is a security concern that will MOST likely need to be addressed during migration?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A security engineer needs to ensure production containers are automatically scanned for vulnerabilities before they are accepted into the production environment. Which of the following should the engineer use to automatically incorporate vulnerability scanning on every commit?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
The Chief Information Security Officer (CISO) at a software company is trying to document the technical and security requirements needed to connect the company's network to an external system. The additional requirements include procedural and planning information. Which of the following should the CISO use to best accomplish this objective?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Leveraging cryptographic solutions to protect data that is in use ensures the data is encrypted:
Correct Answer: C
0
0
0
0