Free CAS-003 Exam Braindumps (page: 46)

Page 46 of 137

A security manager recently categorized an information system. During the categorization effort, the manager determined the loss of integrity of a specific information type would impact business significantly. Based on this, the security manager recommends the implementation of several solutions. Which of the following, when combined, would BEST mitigate this risk? (Choose two.)

  1. Access control
  2. Whitelisting
  3. Signing
  4. Validation
  5. Boot attestation

Answer(s): C,D



A security analyst is reviewing the following company requirements prior to selecting the appropriate technical control configuration and parameter:

RTO: 2 days
RPO: 36 hours
MTTR: 24 hours
MTBF: 60 days

Which of the following solutions will address the RPO requirements?

  1. Remote Syslog facility collecting real-time events
  2. Server farm behind a load balancer delivering five-nines uptime
  3. Backup solution that implements daily snapshots
  4. Cloud environment distributed across geographic regions

Answer(s): C



A penetration test is being scoped for a set of web services with API endpoints. The APIs will be hosted on existing web application servers. Some of the new APIs will be available to unauthenticated users, but some will only be available to authenticated users. Which of the following tools or activities would the penetration tester MOST likely use or do during the engagement? (Choose two.)

  1. Static code analyzer
  2. Intercepting proxy
  3. Port scanner
  4. Reverse engineering
  5. Reconnaissance gathering
  6. User acceptance testing

Answer(s): B,C



A recent overview of the network’s security and storage applications reveals a large amount of data that needs to be isolated for security reasons. Below are the critical applications and devices configured on the network:

-Firewall
-Core switches
-RM server
-Virtual environment
-NAC solution

The security manager also wants data from all critical applications to be aggregated to correlate events from multiple sources. Which of the following must be configured in certain applications to help ensure data aggregation and data isolation are implemented on the critical applications and devices? (Choose two.)

  1. Routing tables
  2. Log forwarding
  3. Data remanants
  4. Port aggregation
  5. NIC teaming
  6. Zones

Answer(s): B,F



Page 46 of 137



Post your Comments and Discuss CompTIA CAS-003 exam with other Community members:

Nathan commented on April 20, 2020
I appreicate that you provide the Xengine software for free. But are you planning to keep it free! I really hope so!
GERMANY
upvote