  • Exam Number: CAS-003
  • Provider: Comptia
  • Questions: 343
  • Updated On: 5-Feb-2019

Topic 1, Main Questions A

A security analyst is reviewing the corporate MDM settings and notices some disabled settings,
which consequently permit users to download programs from untrusted developers and
manual y install them. After some conversations, it is confirmed that these settings were
disabled to support the internal development of mobile applications. The security analyst is now
recommending that developers and testers have a separate device profile allowing this, and that
the rest of the organization's users do not have the ability to manual y download and install
untrusted applications. Which of the following settings should be toggled to achieve the goal?
(Choose two.)

A. OTA updates
B. Remote wiping
C. Side loading
D. Sandboxing
E. Containerization
F. Signed applications

Answer(s): E, F
A penetration tester is conducting an assessment on and runs the following
command from a coffee shop while connected to the public Internet:

Which of the following should the penetration tester conclude about the command output?

A. The public/private views on the DNS servers are misconfigured
B. is running an older mail server, which may be vulnerable to exploits
C. The DNS SPF records have not been updated for
D. is a backup mail server that may be more vulnerable to attack

Answer(s): B
There have been several exploits to critical devices within the network. However, there is
currently no process to perform vulnerability analysis. Which the following should the security
analyst implement during production hours to identify critical threats and vulnerabilities?

A. asset inventory of all critical devices
B. Vulnerability scanning frequency that does not interrupt workflow
C. Daily automated reports of exploited devices

