Free CAS-003 Exam Braindumps (page: 67)

Page 67 of 137

A Chief Information Security Officer (CISO) needs to establish a KRI for a particular system. The system holds archives of contracts that are no longer in use. The contracts contain intellectual property and have a data classification of non-public. Which of the following be the BEST risk indicator for this system?

  1. Average minutes of downtime per quarter
  2. Percent of patches applied in the past 30 days
  3. Count of login failures per week
  4. Number of accounts accessing the system per day

Answer(s): D



Staff members are reporting an unusual number of device thefts associated with time out of the office. Thefts increased soon after the company deployed a new social networking application. Which of the following should the Chief Information Security Officer (CISO) recommend implementing?

  1. Automatic location check-ins
  2. Geolocated presence privacy
  3. Integrity controls
  4. NAC checks to quarantine devices

Answer(s): B



A security engineer is assessing a new IoT product. The product interfaces with the ODBII port of a vehicle and uses a Bluetooth connection to relay data to an onboard data logger located in the vehicle. The data logger can only transfer data over a custom USB cable. The engineer suspects a relay attack is possible against the cryptographic implementation used to secure messages between segments of the system. Which of the following tools should the engineer use to confirm the analysis?

  1. Binary decompiler
  2. Wireless protocol analyzer
  3. Log analysis and reduction tools
  4. Network-based fuzzer

Answer(s): B



A recent security assessment revealed a web application may be vulnerable to clickjacking. According to the application developers, a fix may be months away. Which of the following should a security engineer configure on the web server to help mitigate the issue?

  1. File upload size limits
  2. HttpOnly cookie field
  3. X-Frame-Options header
  4. Input validation

Answer(s): C



Page 67 of 137



Post your Comments and Discuss CompTIA CAS-003 exam with other Community members:

Nathan commented on April 20, 2020
I appreicate that you provide the Xengine software for free. But are you planning to keep it free! I really hope so!
GERMANY
upvote