Comptia

CAS-005 Free Practice Questions — Page 14

Question 131

Due to reports of malware targeting companies in the same industry, an organization wants to develop a comprehensive list of IoCs to determine if its systems might be affected in a similar attack. Which of the following would be best to use to develop this list?

A. Simulators
B. Sandbox detonation
C. Antivirus
D. Endpoint detection and response
Show Answer
Correct Answer: B
Explanation:
Sandbox detonation runs the suspected malware in an isolated environment and observes its behavior, helping analysts extract IoCs such as file hashes, domains, IP addresses, and system changes to check against their own systems.

Question 132

A company created an external application for its customers. A security researcher now reports that the application has a serious LDAP injection vulnerability that could be leveraged to bypass authentication and authorization. Which of the following actions would best resolve the issue? (Choose two.)

A. Conduct input sanitization.
B. Deploy a SIEM.
C. Use containers.
D. Patch the OS.
E. Deploy a WAF.
F. Deploy a reverse proxy.
G. Deploy an IDS.
Show Answer
Correct Answer: A, E
Explanation:
Input sanitization (ideally using safe LDAP query construction and validation) addresses the injection flaw in the application. A WAF can provide an additional protective layer by detecting and blocking LDAP injection payloads while the application is fixed. The other options do not directly remediate this application-layer vulnerability.

Question 133

The management team at a company with a large, aging server environment is conducting a server risk assessment in order to create a replacement strategy. The replacement strategy will be based upon the likelihood a server will fail, regardless of the criticality of the application running on a particular server. Which of the following should be used to prioritize the server replacements?

A. SLE
B. MTTR
C. TCO
D. MTBF
E. MSA
Show Answer
Correct Answer: D
Explanation:
MTBF (mean time between failures) measures the average operating time between failures, so it helps compare server reliability and prioritize servers more likely to fail. The other options measure incident impact, restoration time, ownership cost, or a contractual agreement.

Question 134

A technician is reviewing the logs and notices a large number of files were transferred to remote sites over the course of three months. This activity then stopped. The files were transferred via TLS-protected HTTP sessions from systems that do not send traffic to those sites. The technician will define this threat as:

A. a decrypting RSA using an obsolete and weakened encryption attack.
B. a zero-day attack.
C. an advanced persistent threat.
D. an on-path attack.
Show Answer
Correct Answer: C
Explanation:
The sustained transfer of large volumes of files to unusual remote sites over several months is characteristic of a stealthy, long-term compromise—an advanced persistent threat (APT). The scenario does not indicate that TLS was broken, a zero-day was used, or traffic was intercepted in transit.

Question 135

A company recently migrated its critical web application to a cloud provider’s environment. As part of the company’s risk management program, the company intends to conduct an external penetration test. According to the scope of work and the rules of engagement, the penetration tester will validate the web application’s security and check for opportunities to expose sensitive company information in the newly migrated cloud environment. Which of the following should be the first consideration prior to engaging in the test?

A. Prepare a redundant server to ensure the critical web application’s availability during the test.
B. Obtain agreement between the company and the cloud provider to conduct penetration testing.
C. Ensure the latest patches and signatures are deployed on the web server.
D. Create an NDA between the external penetration tester and the company.
Show Answer
Correct Answer: B
Explanation:
Because the application is hosted in a cloud provider’s environment, the company should first confirm that the provider authorizes the planned penetration test. Testing without the required approval may violate the provider’s terms or affect shared infrastructure. Redundancy, patching, and an NDA may be useful, but they do not replace that authorization.

Question 136

An organization currently has IDS, firewall, and DLP systems in place. The systems administrator needs to integrate the tools in the environment to reduce response time. Which of the following should the administrator use?

A. SOAR
B. CWPP
C. XCCDF
D. CMDB
Show Answer
Correct Answer: A
Explanation:
SOAR (Security Orchestration, Automation, and Response) integrates security tools such as IDS, firewalls, and DLP, and automates workflows to speed up incident response.

Question 137

A security architect is mitigating a vulnerability that previously led to a web application data breach. An analysis into the root cause of the issue finds the following: • An administrator’s account was hijacked and used on several Autonomous System Numbers within 30 minutes. • All administrators use named accounts that require multifactor authentication. • Single sign-on is used for all company applications. Which of the following should the security architect do to mitigate the issue?

A. Configure token theft detections on the single sign-on system with automatic account lockouts.
B. Enable context-based authentication when network locations change on administrator login attempts.
C. Decentralize administrator accounts and force unique passwords for each application.
D. Enforce biometric authentication requirements for the administrator’s named accounts.
Show Answer
Correct Answer: B
Explanation:
Require context-based authentication when an administrator’s network location changes. Rapid use of the account across multiple ASNs is anomalous and may indicate a hijacked session; location-aware checks can trigger additional verification. Biometrics or unique passwords would not stop use of an already-compromised session, and automatic lockouts risk denial-of-service abuse.

Question 138

An administrator reviews the following log and determines the root cause of a site-to-site tunnel failure: Which of the following actions should the administrator take to most effectively correct the failure?

A. Enable perfect forward secrecy on the remote peer.
B. Update the cipher suites configured for use on the server side.
C. Add a new subnet as a permitted initiator.
D. Disable IKE version 1 and run IKE version 2.
Show Answer
Correct Answer: C
Explanation:
The log indicates a traffic-selector mismatch and no matching selector configuration. Add the remote subnet as a permitted initiator so the selectors match. The IKE version and cipher proposals are not the cause.

Question 139

Which of the following most likely explains the reason a security engineer replaced ECC with a lattice-based cryptographic technique?

A. It is computationally efficient and provides perfect forward secrecy.
B. It is more resilient to brute-force attacks than ECC.
C. It supports ephemeral key exchange and digital signatures.
D. It is currently considered a robust PQC technique.
E. It enables processing on data while remaining in an encrypted state.
Show Answer
Correct Answer: D
Explanation:
Lattice-based cryptography is a leading post-quantum approach, designed to resist attacks from quantum computers that threaten ECC. The other options describe properties ECC may also provide or refer to homomorphic encryption.

Question 140

After several companies in the financial industry were affected by a similar incident, they shared information about threat intelligence and the malware used for exploitation. Which of the following should the companies do to best indicate whether the attacks are being conducted by the same actor?

A. Apply code stylometry.
B. Look for common TTPs.
C. Use IoC extractions.
D. Leverage malware detonation.
Show Answer
Correct Answer: B
Explanation:
Compare the incidents for common tactics, techniques, and procedures (TTPs). Consistent behavioral patterns are more useful for assessing whether the same actor is responsible than shared or changeable indicators such as hashes, IP addresses, or domains.

$19

Get all 400 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.