Free CAS-003 Exam Braindumps (page: 35)

Page 35 of 137

A company has gone through a round of phishing attacks. More than 200 users have had their workstation infected because they clicked on a link in an email. An incident analysis has determined an executable ran and compromised the administrator account on each workstation. Management is demanding the information security team prevent this from happening again.

Which of the following would BEST prevent this from happening again?

  1. Antivirus
  2. Patch management
  3. Log monitoring
  4. Application whitelisting
  5. Awareness training

Answer(s): E



An internal staff member logs into an ERP platform and clicks on a record. The browser URL changes to:

URL: http://192.168.0.100/ERP/accountId=5&action=SELECT

Which of the following is the MOST likely vulnerability in this ERP platform?

  1. Brute forcing of account credentials
  2. Plain-text credentials transmitted over the Internet
  3. Insecure direct object reference
  4. SQL injection of ERP back end

Answer(s): C



Providers at a healthcare system with many geographically dispersed clinics have been fined five times this year after an auditor received notice of the following SMS messages:


Which of the following represents the BEST solution for preventing future fines?

  1. Implement a secure text-messaging application for mobile devices and workstations.
  2. Write a policy requiring this information to be given over the phone only.
  3. Provide a courier service to deliver sealed documents containing public health informatics.
  4. Implement FTP services between clinics to transmit text documents with the information.
  5. Implement a system that will tokenize patient numbers.

Answer(s): A



An information security manager is concerned that connectivity used to configure and troubleshoot critical network devices could be attacked. The manager has tasked a network security engineer with meeting the following requirements:

-Encrypt all traffic between the network engineer and critical devices.
-Segregate the different networking planes as much as possible.
-Do not let access ports impact configuration tasks.

Which of the following would be the BEST recommendation for the network security engineer to present?

  1. Deploy control plane protections.
  2. Use SSH over out-of-band management.
  3. Force only TACACS to be allowed.
  4. Require the use of certificates for AAA.

Answer(s): B



Page 35 of 137



Post your Comments and Discuss CompTIA CAS-003 exam with other Community members:

Nathan commented on April 20, 2020
I appreicate that you provide the Xengine software for free. But are you planning to keep it free! I really hope so!
GERMANY
upvote