Summer Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dealsixty

Legit CAS-003 Exam Download

Page: 12 / 25
Question 48

A security analyst is reviewing the logs from a NIDS. the analyst notices the following in quick succession between a client and a web server.

Which of the following describes what MOST likely occurred and offers a mitigation?

Options:

A.

A protocol downgrade attack which can be mitigated by disabling server and client support for older protocols

B.

A MITM SSL stripping attack which can be mitigated by enabling HSTS on the web server

C.

A broadcast RC4 attack which can be mitigated by disabling cipher suites permitting the use of RC4

D.

An attack on TLS compression revealing cipher text which can be mitigated by implementing a TLS proxy or removing compression characteristics

Question 49

Which of the following is a major goal of stakeholder engagement?

Options:

A.

Completing risk compliance outreach and understanding

B.

Determining which security requirements can be deferred safety

C.

Ensuring security requirements are supportive of business goals

D.

Understanding the best way to limit user privilege escalation

Question 50

Company policy dictates that events from at least the past three months must be stored centrally for review. When a security incident occurs the security analyst investigates the underlying cause and sees the following:

The error appears to have started five days ago at the centralized location. Which of the following would prevent this issue from reoccurring?

Options:

A.

Log reduction and analysis

B.

Host-based IDS

C.

SCAP scanner

D.

File integrity monitoring

Question 51

A product development team has submitted code snippets for review prior to release.

INSTRUCTIONS -

Analyze the code snippets, and then select one vulnerability, and one fix for each code snippet.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Options:

Page: 12 / 25
Exam Code: CAS-003
Exam Name: CompTIA Advanced Security Practitioner (CASP) Exam
Last Update: Apr 14, 2023
Questions: 683
CAS-003 pdf

CAS-003 PDF

$32  $80
CAS-003 Engine

CAS-003 Testing Engine

$38  $95
CAS-003 PDF + Engine

CAS-003 PDF + Testing Engine

$52  $130