Free CAS-003 Exam Braindumps (page: 63)

Page 63 of 137

A security engineer is analyzing an application during a security assessment to ensure it is configured to protect against common threats. Given the output below:


Which of the following tools did the security engineer MOST likely use to generate this output?

  1. Application fingerprinter
  2. Fuzzer
  3. HTTP interceptor
  4. Vulnerability scanner

Answer(s): C



The Chief Financial Officer (CFO) of a major hospital system has received a ransom letter that demands a large sum of cryptocurrency be transferred to an anonymous account. If the transfer does not take place within ten hours, the letter states that patient information will be released on the dark web. A partial listing of recent patients is included in the letter. This is the first indication that a breach took place. Which of the following steps should be done FIRST?

  1. Review audit logs to determine the extent of the breach
  2. Pay the hacker under the condition that all information is destroyed
  3. Engage a counter-hacking team to retrieve the data
  4. Notify the appropriate legal authorities and legal counsel

Answer(s): D



A project manager is working with system owners to develop maintenance windows for system patching and upgrades in a cloud-based PaaS environment. Management has indicated one maintenance windows will be authorized per month, but clients have stated they require quarterly maintenance windows to meet their obligations. Which of the following documents should the project manager review?

  1. MOU
  2. SOW
  3. SRTM
  4. SLA

Answer(s): D



A Chief Information Security Officer (CISO) is working with a consultant to perform a gap assessment prior to an upcoming audit. It is determined during the assessment that the organization lacks controls to effectively assess regulatory compliance by third-party service providers. Which of the following should be revised to address this gap?

  1. Privacy policy
  2. Work breakdown structure
  3. Interconnection security agreement
  4. Vendor management plan
  5. Audit report

Answer(s): D



Page 63 of 137



Post your Comments and Discuss CompTIA CAS-003 exam with other Community members:

Nathan commented on April 20, 2020
I appreicate that you provide the Xengine software for free. But are you planning to keep it free! I really hope so!
GERMANY
upvote