Comptia

CAS-005 Free Practice Questions — Page 10

Question 91

Audit findings indicate several user endpoints are not utilizing full disk encryption. During the remediation process, a compliance analyst reviews the testing details for the endpoints and notes the endpoint device configuration does not support full disk encryption. Which of the following is the most likely reason the device must be replaced?

A. The HSM is outdated and no longer supported by the manufacturer
B. The vTPM was not properly initialized and is corrupt.
C. The HSM is vulnerable to common exploits and a firmware upgrade is needed
D. The motherboard was not configured with a TPM from the OEM supplier
E. The HSM does not support sealing storage
Show Answer
Correct Answer: D
Explanation:
Full-disk encryption commonly relies on a TPM to securely store or seal encryption keys. If the motherboard was supplied without a TPM and cannot support one, the endpoint lacks required hardware and may need replacement.

Question 92

An organization has noticed an increase in phishing campaigns utilizing typosquatting. A security analyst needs to enrich the data for commonly used domains against the domains used in phishing campaigns. The analyst uses a log forwarder to forward network logs to the SIEM. Which of the following would allow the security analyst to perform this analysis?

A. Use a cron job to regularly update and compare domains.
B. Create a parser that matches domains.
C. Develop a query that filters out all matching domain names.
D. Implement a dashboard on the SIEM that shows the percentage of traffic by domain.
Show Answer
Correct Answer: C
Explanation:
A SIEM query can filter network-log events by domain and compare observed domains with known phishing or legitimate-domain data. A parser extracts fields, while a dashboard only visualizes traffic; neither performs the comparison.

Question 93

After remote desktop capabilities were deployed in the environment various vulnerabilities were noticed: • Exfiltration of intellectual property • Unencrypted files • Weak user passwords Which of the following is the best way to mitigate these vulnerabilities? (Choose two.)

A. Implementing data loss prevention
B. Deploying file integrity monitoring
C. Restricting access to critical file services only
D. Deploying directory-based group policies
E. Enabling modem authentication that supports MFA
F. Implementing a version control system
G. Implementing a CMDB platform
Show Answer
Correct Answer: A, D
Explanation:
Data loss prevention helps prevent intellectual property from being exfiltrated. Directory-based group policies can enforce stronger passwords and file-encryption requirements across remote desktop users and systems.

Question 94

A security architect wants to develop a baseline of security configurations. These configurations automatically will be utilized every time a new virtual machine is created. Which of the following technologies should the security architect deploy to accomplish this goal?

A. Snort
B. CASВ
C. Ansible
D. CMDB
Show Answer
Correct Answer: C
Explanation:
Ansible can define security baselines as configuration-management playbooks and automatically apply them when new virtual machines are provisioned. Snort is an intrusion detection/prevention tool, a CASB secures cloud service use, and a CMDB tracks configuration items.

Question 95

A game developer wants to reach new markets and is advised by legal counsel to include specific age-related sign-up requirements. Which of the following best describes the legal counsel's concerns?

A. GDPR
B. LGPD
C. PCI DSS
D. COPPA
Show Answer
Correct Answer: D
Explanation:
COPPA applies to covered online services collecting personal information from children under 13 in the United States. It requires parental consent and related protections, which can mean age-related sign-up measures.

Question 96

A security analyst is reviewing the following authentication logs: Which of the following should the analyst do first?

A. Disable User2’s account.
B. Disable User12’s account
C. Disable User8’s account
D. Disable User1’s account
Show Answer
Correct Answer: D
Explanation:
Disable User1’s account first. Multiple rapid failed login attempts followed by a successful login can indicate a brute-force attack that succeeded, so the account should be contained promptly.

Question 97

The material findings from a recent compliance audit indicate a company has an issue with excessive permissions. The findings show that employees changing roles or departments results in privilege creep. Which of the following solutions are the best ways to mitigate this issue? (Choose two.)

A. Setting different access controls defined by business area
B. Implementing a role-based access policy
C. Designing a least-needed privilege policy
D. Establishing a mandatory vacation policy
E. Performing periodic access reviews
F. Requiring periodic job rotation
Show Answer
Correct Answer: B, E
Explanation:
Role-based access control ties permissions to a person’s current role, reducing the chance that old permissions carry over when they change jobs. Periodic access reviews can identify and remove permissions that are no longer needed. Together, these directly address privilege creep.

Question 98

A company implemented a NIDS and a NIPS on the most critical environments. Since this implementation the company has been experiencing network connectivity issues. Which of the following should the security architect recommend for a new NIDS/NIPS implementation?

A. Implementing the NIDS with a port mirror in the core switch and the NIPS in the main firewall
B. Implementing the NIDS and the NIPS together with the main firewall
C. Implementing a NIDS without a NIPS to increase the detection capability
D. Implementing the NIDS in the bastion host and the NIPS in the branch network router
Show Answer
Correct Answer: A
Explanation:
A NIDS connected to a switch port mirror monitors traffic passively, so it cannot disrupt forwarding. A NIPS is inline and can block malicious traffic; placing it at the main firewall provides a controlled enforcement point. Separating the passive detection sensor from inline prevention helps reduce connectivity impact.

Question 99

A security analyst reviews the following event timeline from an EDR solution: Which of the following has most likely occurred and needs to be fixed?

A. The DLP has failed to block malicious exfiltration, and data tagging is not being utilized properly.
B. A NIDS bypass was utilized by a threat actor, and updates must be installed by the administrator.
C. A logic flaw has introduced a TOCTOU vulnerability and must be addressed by the vendor.
D. A potential insider threat is being investigated and will be addressed by the senior management team.
Show Answer
Correct Answer: C
Explanation:
The file was executed and launched a script before the security scan finished and identified it as malicious. This check-then-use timing gap is a TOCTOU logic flaw that should be addressed by the vendor.

Question 100

A company hosts a platform-as-a-service solution with a web-based front end, through which customers interact with data sets. A security administrator needs to deploy controls to prevent application-focused attacks. Which of the following most directly supports the administrator’s objective?

A. Improving security dashboard visualization on SIEM
B. Rotating API access and authorization keys every two months
C. Implementing application load balancing and cross-region availability
D. Creating WAF policies for relevant programming languages
Show Answer
Correct Answer: D
Explanation:
A web application firewall (WAF) filters and blocks application-layer attacks against the platform’s web front end. The other options address monitoring, credential hygiene, or availability rather than directly preventing application-focused attacks.

$19

Get all 400 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.