Free CAS-003 Exam Braindumps (page: 12)

Page 12 of 137

A security consultant is attempting to discover if the company is utilizing databases on client machines to store the customer data. The consultant reviews the following information:


Which of the following commands would have provided this output?

  1. arp -s
  2. netstat -a
  3. ifconfig -arp
  4. sqlmap -w

Answer(s): B



Management is reviewing the results of a recent risk assessment of the organization’s policies and procedures. During the risk assessment it is determined that procedures associated with background checks have not been effectively implemented. In response to this risk, the organization elects to revise policies and procedures related to background checks and use a third-party to perform background checks on all new employees.
Which of the following risk management strategies has the organization employed?

  1. Transfer
  2. Mitigate
  3. Accept
  4. Avoid
  5. Reject

Answer(s): B



A company wants to perform analysis of a tool that is suspected to contain a malicious payload. A forensic analyst is given the following snippet:

^32^[34fda19(fd^43gfd/home/user/lib/module.so.343jk^rfw(342fds43g

Which of the following did the analyst use to determine the location of the malicious payload?

  1. Code deduplicators
  2. Binary reverse-engineering
  3. Fuzz testing
  4. Security containers

Answer(s): B



An advanced threat emulation engineer is conducting testing against a client’s network. The engineer conducts the testing in as realistic a manner as possible. Consequently, the engineer has been gradually ramping up the volume of attacks over a long period of time. Which of the following combinations of techniques would the engineer MOST likely use in this testing? (Choose three.)

  1. Black box testing
  2. Gray box testing
  3. Code review
  4. Social engineering
  5. Vulnerability assessment
  6. Pivoting
  7. Self-assessment
  8. White teaming
  9. External auditing

Answer(s): A,E,F



Page 12 of 137



Post your Comments and Discuss CompTIA CAS-003 exam with other Community members:

Nathan commented on April 20, 2020
I appreicate that you provide the Xengine software for free. But are you planning to keep it free! I really hope so!
GERMANY
upvote