CompTIA Advanced Security Practitioner (CASP) - CAS-003 Exam Practice Test
Given the following output from a security tool in Kali:


Correct Answer: D
Vote an answer
A company wants to analyze internal network traffic for IOCs. The security solution consists of a network collector appliance and a separate server which security analysts access via a browser to visualize and review the alerts generated from the network traffic. The company uses a collapsed core operating at Layer 2 at 100Gbps. The server win be placed in the datacenter. Which of the following architectures should be used to ensure the solution can provide visibility into all the company's internal network traffic including DNS and URL requests without impacting network traffic flow?
Correct Answer: B
Vote an answer
An enterprise is trying to secure a specific web-based application by forcing the use of multifactor authentication. Currently, the enterprise cannot change the application's sign-in page to include an extra field. However, the web-based application supports SAML. Which of the following would BEST secure the application?
Correct Answer: B
Vote an answer
A security administrator wants to implement controls to harden company-owned mobile devices. Company policy specifies the following requirements:
Mandatory access control must be enforced by the OS.
Devices must only use the mobile carrier data transport.
Which of the following controls should the security administrator implement? (Select three).
Mandatory access control must be enforced by the OS.
Devices must only use the mobile carrier data transport.
Which of the following controls should the security administrator implement? (Select three).
Correct Answer: D,F,H
Vote an answer
Following a recent disaster a business activates its DRP. The business is operational again within 60 minutes. The business has multiple geographically dispersed locations that have similar equipment and operational capabilities. Which of the following strategies has the business implemented?
Correct Answer: D
Vote an answer
A company that uses AD is migrating services from LDAP to secure LDAP. During the pilot phase, services are not connecting properly to secure LDAP. Block is an except of output from the troubleshooting session:

Which of the following BEST explains why secure LDAP is not working? (Select TWO.)

Which of the following BEST explains why secure LDAP is not working? (Select TWO.)
Correct Answer: B,E
Vote an answer
An organization recently experienced losses caused by users who installed applications from unauthorized sources on their smartphones. The organization wants to reduce the risk of reoccurrence but increase the monitoring and reporting of mobile device security at the enterprise level. Which of the following approaches would BEST meet these objectives?
Correct Answer: C
Vote an answer
The government is concerned with remote military missions being negatively being impacted by the use of technology that may fail to protect operational security. To remediate this concern, a number of solutions have been implemented, including the following:
End-to-end encryption of all inbound and outbound communication, including personal email and chat sessions that allow soldiers to securely communicate with families.
Layer 7 inspection and TCP/UDP port restriction, including firewall rules to only allow TCP port 80 and 443 and approved applications A host-based whitelist of approved websites and applications that only allow mission-related tools and sites The use of satellite communication to include multiple proxy servers to scramble the source IP address Which of the following is of MOST concern in this scenario?
End-to-end encryption of all inbound and outbound communication, including personal email and chat sessions that allow soldiers to securely communicate with families.
Layer 7 inspection and TCP/UDP port restriction, including firewall rules to only allow TCP port 80 and 443 and approved applications A host-based whitelist of approved websites and applications that only allow mission-related tools and sites The use of satellite communication to include multiple proxy servers to scramble the source IP address Which of the following is of MOST concern in this scenario?
Correct Answer: A
Vote an answer
A cloud architect needs to isolate the most sensitive portion of the network while maintaining hosting in a public cloud Which of the following configurations can be employed to support this effort?
Correct Answer: D
Vote an answer
A secure facility has a server room that currently is controlled by a simple lock and key. and several administrators have copies of the key. To maintain regulatory compliance, a second lock, which is controlled by an application on the administrators' smartphones, is purchased and installed. The application has various authentication methods that can be used. The criteria for choosing the most appropriate method are:
* It cannot be invasive to the end user
* It must be utilized as a second factor.
* Information sharing must be avoided
* It must have a low false acceptance rate
Which of the following BEST meets the criteria?
* It cannot be invasive to the end user
* It must be utilized as a second factor.
* Information sharing must be avoided
* It must have a low false acceptance rate
Which of the following BEST meets the criteria?
Correct Answer: E
Vote an answer