Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

CompTIA CASP CAS-003 Exam Dumps

Page: 13 / 25
Question 52

A company is implementing a new MFA initiative. The requirements for the second factor ate as folio.*.s

• It cannot be phished

• it must work as a second factor for laptop logins

• It must be something the user has

Which of the following solutions should the company choose?

Options:

A.

User biometrics

B.

U2F hardware keys

C.

TOTP hardware keys

D.

Push ratification to a mobile device

E.

SMS notification to a managed device

Question 53

A Chief Security Officer (CSO) is reviewing the organization’s incident response report from a recent incident. The details of the event indicate:

  • A user received a phishing email that appeared to be a report from the organization’s CRM tool.
  • The user attempted to access the CRM tool via a fraudulent web page but was unable to access the tool.
  • The user, unaware of the compromised account, did not report the incident and continued to use the CRM tool with the original credentials.
  • Several weeks later, the user reported anomalous activity within the CRM tool.
  • Following an investigation, it was determined the account was compromised and an attacker in another country has gained access to the CRM tool.
  • Following identification of corrupted data and successful recovery from the incident, a lessons learned activity was to be led by the CSO.

Which of the following would MOST likely have allowed the user to more quickly identify the unauthorized use of credentials by the attacker?

Options:

A.

Security awareness training

B.

Last login verification

C.

Log correlation

D.

Time-of-check controls

E.

Time-of-use controls

F.

WAYF-based authentication

Question 54

A company has deployed MFA Some employees, however, report they ate not gelling a notification on their mobile device Other employees report they downloaded a common authenticates application but when they tap the code in the application it just copies the code to memory instead of confirming the authentication attempt Which of the following are the MOST likely explanations for these scenarios? (Select TWO)

Options:

A.

The company is using a claims-based authentication system for MFA

B.

These are symptoms of known compatibility issues with OAuth 1 0

C.

OpenID Connect requires at least one factor to be a biometric

D.

The company does not allow an SMS authentication method

E.

The WAYF method requires a third factor before the authentication process can complete

F.

A vendor-specific authenticator application is needed for push notifications

Question 55

Given the following output from a security tool in Kali:

Options:

A.

Log reduction

B.

Network enumerator

C.

Fuzzer

D.

SCAP scanner

Page: 13 / 25
Exam Code: CAS-003
Exam Name: CompTIA Advanced Security Practitioner (CASP) Exam
Last Update: Apr 14, 2023
Questions: 683
CAS-003 pdf

CAS-003 PDF

$28  $80
CAS-003 Engine

CAS-003 Testing Engine

$33.25  $95
CAS-003 PDF + Engine

CAS-003 PDF + Testing Engine

$45.5  $130