CompTIA SecurityX Certification - CAS-005 Exam Practice Test

An organization handles sensitive information that must be displayed on call center technicians' screens to verify the identities of remote callers. The technicians use three randomly selected fields of information to complete the identity verification process. Some of the fields contain PII that are unique identifiers for the remote callers. Which of the following should be implemented to identify remote callers while also reducing the risk that technicians could improperly use the identification information?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
SIMULATION
A product development team has submitted code snippets for review prior to release.
INSTRUCTIONS
Analyze the code snippets, and then select one vulnerability, and one fix for each code snippet.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Code Snippet 1

Code Snippet 2

Correct Answer:
Incident responders determine that a company email server was the first compromised machine in an attack. The server was infected by malware. The following are abbreviated headers from three emails that the incident responders could not confidently determine to be safe:

Which of the following is the most likely reason the malware was delivered?
Correct Answer: B
A security manager has written an incident response playbook for insider attacks and is ready to begin testing it. Which of the following should the manager conduct to test the playbook?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An organization has deployed a cloud-based application that provides virtual event services globally to clients. During a typical event, thousands of users access various entry pages within a short period of time. The entry pages include sponsor-related content that is relatively static and is pulled from a database. When the first major event occurs, users report poor response time on the entry pages. Which of the following features is the most appropriate for the company to implement?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An organization currently has IDS, firewall, and DLP systems in place. The systems administrator needs to integrate the tools in the environment to reduce response time. Which of the following should the administrator use?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A security administrator is reviewing the following code snippet from a website component:

A review of the inc.tmp file shows the following:

Which of the following is most likely the reason for inaccuracies?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A company recently acquired a SaaS company and performed a gap analysis. The results of the gap analysis Indicate security controls are absent throughout the SDLC and have led to several vulnerable production releases. Which of the following security tools best reduces the risk of vulnerable code being pushed to production in the future?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An organization is developing a disaster recovery plan that requires data to be backed up and available at a moment's notice. Which of the following should the organization consider first to address this requirement?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A security consultant recommends that a solution be deployed to increase awareness of APTs throughout the IT and OT environments. The consultant's requirements state that the solution must:
- Be capable of collecting data from both OT and IT protocols.
- Operate within new microsegmented and air-gapped network architecture
- Provide both correlation of events and retention of raw log data and
incidents
- Integrate with the ITSM platform and employee paging system
Which of the following solutions best meets these requirements?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A security engineer must reduce overhead of routine security administration tasks with SOAR.
Which of the following should the engineer do to best meet this objective?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An organization is looking to establish more robust security measures by implementing PKI.
Which of the following should the security analyst implement when considering mutual authentication?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A company detects suspicious activity associated with inbound connections. Security detection tools are unable to categorize this activity. Which of the following is the best solution to help the company overcome this challenge?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which of the following cryptographic techniques is the most resistant to quantum computing decryption attacks?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
0
0
0
0