Free CAS-003 Exam Braindumps (page: 76)

Page 76 of 137

After significant vulnerabilities and misconfigurations were found in numerous production web applications, a security manager identified the need to implement better development controls.
Which of the following controls should be verified? (Choose two.)

  1. Input validation routines are enforced on the server side.
  2. Operating systems do not permit null sessions.
  3. Systems administrators receive application security training.
  4. VPN connections are terminated after a defined period of time.
  5. Error-handling logic fails securely.
  6. OCSP calls are handled effectively.

Answer(s): A,E



An organization wants to arm its cybersecurity defensive suite automatically with intelligence on zero-day threats shortly after they emerge. Acquiring tools and services that support which of the following data standards would BEST enable the organization to meet this objective?

  1. XCCDF
  2. OVAL
  3. STIX
  4. CWE
  5. CVE

Answer(s): E



A financial institution’s information security officer is working with the risk management officer to determine what to do with the institution’s residual risk after all security controls have been implemented. Considering the institution’s very low risk tolerance, which of the following strategies would be BEST?

  1. Transfer the risk.
  2. Avoid the risk
  3. Mitigate the risk.
  4. Accept the risk.

Answer(s): A



A large, public university has recently been experiencing an increase in ransomware attacks against computers connected to its network. Security engineers have discovered various staff members receiving seemingly innocuous files in their email that are being run. Which of the following would BEST mitigate this attack method?

  1. Improving organizations email filtering
  2. Conducting user awareness training
  3. Upgrading endpoint anti-malware software
  4. Enabling application whitelisting

Answer(s): B



Page 76 of 137



Post your Comments and Discuss CompTIA CAS-003 exam with other Community members:

Nathan commented on April 20, 2020
I appreicate that you provide the Xengine software for free. But are you planning to keep it free! I really hope so!
GERMANY
upvote