Free CAS-003 Exam Braindumps (page: 40)

Page 40 of 137

A security engineer is attempting to increase the randomness of numbers used in key generation in a system. The goal of the effort is to strengthen the keys against predictive analysis attacks.

Which of the following is the BEST solution?

  1. Use an entropy-as-a-service vendor to leverage larger entropy pools.
  2. Loop multiple pseudo-random number generators in a series to produce larger numbers.
  3. Increase key length by two orders of magnitude to detect brute forcing.
  4. Shift key generation algorithms to ECC algorithms.

Answer(s): A



A security engineer is attempting to convey the importance of including job rotation in a company’s standard security policies. Which of the following would be the BEST justification?

  1. Making employees rotate through jobs ensures succession plans can be implemented and prevents single points of failure.
  2. Forcing different people to perform the same job minimizes the amount of time malicious actions go undetected by forcing malicious actors to attempt collusion between two or more people.
  3. Administrators and engineers who perform multiple job functions throughout the day benefit from being cross-trained in new job areas.
  4. It eliminates the need to share administrative account passwords because employees gain administrative rights as they rotate into a new job area.

Answer(s): B



A company is transitioning to a new VDI environment, and a system engineer is responsible for developing a sustainable security strategy for the VDIs.

Which of the following is the MOST appropriate order of steps to be taken?

  1. Firmware update, OS patching, HIDS, antivirus, baseline, monitoring agent
  2. OS patching, baseline, HIDS, antivirus, monitoring agent, firmware update
  3. Firmware update, OS patching, HIDS, antivirus, monitoring agent, baseline
  4. Baseline, antivirus, OS patching, monitoring agent, HIDS, firmware update

Answer(s): A



The Chief Information Officer (CIO) has been asked to develop a security dashboard with the relevant metrics. The board of directors will use the dashboard to monitor and track the overall security posture of the organization. The CIO produces a basic report containing both KPI and KRI data in two separate sections for the board to review.

Which of the following BEST meets the needs of the board?

  1. KRI:
    - Compliance with regulations
    - Backlog of unresolved security investigations
    - Severity of threats and vulnerabilities reported by sensors
    - Time to patch critical issues on a monthly basis KPI:
    - Time to resolve open security items
    - % of suppliers with approved security control frameworks
    - EDR coverage across the fleet
    - Threat landscape rating
  2. KRI:
    - EDR coverage across the fleet
    - Backlog of unresolved security investigations
    - Time to patch critical issues on a monthly basis
    - Threat landscape rating KPI:
    - Time to resolve open security items
    - Compliance with regulations
    - % of suppliers with approved security control frameworks
    - Severity of threats and vulnerabilities reported by sensors
  3. KRI:
    - EDR coverage across the fleet
    - % of suppliers with approved security control framework
    - Backlog of unresolved security investigations
    - Threat landscape rating KPI:
    - Time to resolve open security items
    - Compliance with regulations
    - Time to patch critical issues on a monthly basis
    - Severity of threats and vulnerabilities reported by sensors
  4. KPI:
    - Compliance with regulations
    - % of suppliers with approved security control frameworks
    - Severity of threats and vulnerabilities reported by sensors
    - Threat landscape rating KRI:
    - Time to resolve open security items
    - Backlog of unresolved security investigations
    - EDR coverage across the fleet
    - Time to patch critical issues on a monthly basis

Answer(s): A



Page 40 of 137



Post your Comments and Discuss CompTIA CAS-003 exam with other Community members:

Nathan commented on April 20, 2020
I appreicate that you provide the Xengine software for free. But are you planning to keep it free! I really hope so!
GERMANY
upvote