CompTIA SecurityX Certification - CAS-005 Exam Practice Test

An analyst is using the Diamond Model of Intrusion Analysis to identify the likely chain of activities associated with an attacker's activities. The threat hunter has completed the core components of the model but needs to consider meta factors to more deeply understand the situation. Which of the following should the threat hunter seek to understand within the model?

Correct Answer: C Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Employees use their badges to track the number of hours they work. The badge readers cannot be upgraded due to facility constraints. The software for the badge readers uses a legacy platform and requires connectivity to the enterprise resource planning solution. Which of the following is the best to ensure the security of the badge readers?

Correct Answer: C Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A security engineer is reviewing the SIEM logs after a server crashed. The following list of events represents the timeline of actions collected from the SIEM:

Which of the following TTPs is most likely associated with this SIEM log?

Correct Answer: A Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
An organization plans to deploy new software. The project manager compiles a list of roles that will be involved in different phases of the deployment life cycle. Which of the following should the project manager use to track these roles?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A security engineer would like to control configurations on mobile devices while fulfilling the following requirements:
- Support and control Apple and Android devices.
- The device must be corporate-owned.
Which of the following would enable the engineer to meet these requirements? (Choose two.)

Correct Answer: C,E Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A company implemented a new NAC solution based on 802.1X. However, the IT support team notices that some devices are not being enrolled in the new policies, causing access disruptions for key users. Which of the following solutions will most likely solve this issue and prevent reoccurrence?

Correct Answer: C Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which of the following best explains why AI output could be inaccurate?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A security analyst reviews the following report:

Which of the following assessments is the analyst performing?

Correct Answer: C Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A security administrator needs to develop a remediation plan to address a large number of vulnerability scan results. Which of the following should the administrator use to determine the vulnerabilities that should be addressed first?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Source code snippets for two separate malware samples are shown below:

Which of the following describes the most important observation about the two samples?

Correct Answer: A Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A security architect is onboarding a new EDR agent on servers that traditionally do not have internet access. In order for the agent to receive updates and report back to the management console, some changes must be made. Which of the following should the architect do to best accomplish this requirement? (Choose two.)

Correct Answer: B,F Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A system of globally distributed certificate servers connected to HSMs provide certificate security services for a publicly available PKI. These services include OCSP, certificate revocation list issuance, and certificate signing/issuance. The HSMs are all physical devices. All other servers are virtualized. Each global site has a network load balancer, and the sites are configured to load balance between sites.
Users report occasional but persistent log-on failures to different PKI-enabled websites. There is no apparent pattern to the failures. Some OCSP responses must be signed by the HSM. Each HSM is connected to a physical server containing multiple VMs for the local site with CAT 6e network cable. The backplane connecting the VMs is fiber based.
Which of the following would best reduce the OCSP response time in order to rule out the connection between the certificate server and HSM as a cause of the user-reported issues?

Correct Answer: D Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
After a recent outage, a software engineering company performed an audit of its development processes. The audit findings include the following:
- The use of local branches were not enforced for software development.
- Two-person review was not required for merges with production
pipelines.
- There was a lack of pre-production pipelines and insufficient bake
times between stages.
Which of the following changes would best improve the company's practices?

Correct Answer: A Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
SIMULATION
An IPSec solution is being deployed. The configuration files for both the VPN concentrator and the AAA server are shown in the diagram.
Complete the configuration files to meet the following requirements:
- The EAP method must use mutual certificate-based authentication (with issued client certificates).
- The IKEv2 cipher suite must be configured to the MOST secure authenticated mode of operation.
- The secret must contain at least one uppercase character, one lowercase character, one numeric character, and one special character, and it must meet a minimum length requirement of eight characters.
INSTRUCTIONS
Click on the AAA server and VPN concentrator to complete the configuration. Fill in the appropriate fields and make selections from the drop-down menus.
If at any time you would like to bung back the initial state of the simulation, please click the Reset All button.


Correct Answer:
VPN Concentrator
Proposal: aes256gcm128

Server IP: 10.1.0.10 (this is the AAA server)

Secret: Str0ng@Key (example that meets all character requirements)

AAA Server
Default EAP type: tls

IP Address: 10.1.2.1 (this is the VPN concentrator)

Secret: Str0ng@Key (must match the VPN concentrator)

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday

Support: Contact now 

日本語 Deutsch 繁体中文 한국어