Comptia

CAS-005 Free Practice Questions — Page 4

Question 31

A compliance manager is planning an engagement to identify risks in the environment. The manager wants to discuss with business unit leaders essential aspects of the engagement that include identifying critical assets and processes as well as potential points of failure. Which of the following would be most relevant to consider during these conversations?

A. Subprocessor risks
B. Risk acceptance criteria
C. Remediation strategies
D. Risk appetite and tolerance
Show Answer
Correct Answer: D
Explanation:
Risk appetite and tolerance help determine how much risk the organization is willing and able to accept, and therefore help leaders identify which assets, processes, and failure points are most critical. Subprocessor risks and remediation strategies are narrower or later-stage considerations.

Question 32

A network security architect is working on capturing network traffic to support the following objectives in the pictured network: • Capture relevant traffic to share with a threat intelligence vendor. • Collect only traffic that could indicate a potential network intrusion. • Minimize the budget and resource requirements of the collected traffic. Which of the following is the best way for the network security architect to capture network traffic?

A. Placing a network tap on the ISP router
B. Configuring a span port on the core switch
C. Deploying a transparent proxy on the firewall
D. Connecting a network hub to the IDS device
Show Answer
Correct Answer: B
Explanation:
A SPAN port can mirror selected switch ports or VLANs, allowing the architect to limit the captured traffic to relevant network segments without purchasing a dedicated tap. This makes it the most practical, budget-conscious option; the mirrored traffic can then be analyzed to identify and share intrusion-related activity.

Question 33

A small number but steady series of attempts to breach the network has been occurring over a long period of time. During an investigation, a SOC analyst finds that traffic is exiting the network to known malicious hosts and is originating from a rogue network device. Which of the following attack vectors is most likely being used to breach the network?

A. Supply chain
B. Buffer overflow
C. Social engineering
D. Ransomware
Show Answer
Correct Answer: A
Explanation:
A rogue network device communicating with known malicious hosts suggests a compromised or malicious device introduced into the environment, making a supply-chain attack the best fit. The evidence does not specifically indicate a buffer overflow, social engineering, or ransomware.

Question 34

The Chief Information Security Officer (CISO) asks the security team whether their SOC is receiving IoCs from an industry ISAC Which of the following is the most likely reason the CISO is interested in obtaining this information?

A. To ensure the SOC is able to detect known attacks against similar organizations
B. To ensure the SOC is proactively preventing potential attacks
C. To ensure the SOC orchestration playbooks are up to date
D. To ensure the SOC is aligned with industry best practices
Show Answer
Correct Answer: A
Explanation:
An industry ISAC shares threat intelligence, including indicators of compromise (IoCs) observed across peer organizations. The SOC can use these IoCs to detect known attacks that may also target similar organizations.

Question 35

The following vulnerability was detected during a recent SAST scan of an application that provides an encrypted tunnel between sites: Cipher Block Chaining Initialization Vector must be unpredictable. This vulnerability was found on the following lines of the source code: iv = b"CompTIAIV202512" cipher= Cipher(Algorithms.AES(key), modes.CBC(iv)) Which of the following is the potential impact of this vulnerability?

A. An attacker could derive plaintext from the protected data.
B. An attacker could predict future key material.
C. An attacker could tamper with the value sent in the Initialization Vector variable.
D. An attacker could use a DoS by predicting the Initialization Vector and tampering with its value.
Show Answer
Correct Answer: A
Explanation:
A fixed, predictable CBC initialization vector can reveal patterns in encrypted messages and enable an attacker to infer or test guesses about plaintext. It does not reveal future key material or, by itself, enable IV tampering or a DoS attack. As written, the IV is also only 15 bytes, so AES-CBC would reject it; the intended impact of a predictable IV is loss of confidentiality. Sources: https://docs.bearer.com/reference/rules/php_lang_cbc_predictable_iv https://www.devx.com/terms/cipher-block-chaining

Question 36

A Chief Information Security Officer (CISO) is developing a third-party risk management program and wants to establish an order of preference for solicitation and acceptance of audit and assessment results from business partners. The CISO prefers a formal certification against an established framework, which should be considered more reliable than self-attestations. Which of the following is most likely the reason for this perspective?

A. Certifications are typically issued against a formal standard.
B. Assessments are based on evidence, not judgments.
C. For standards like PCI. self-attestations are more reliable than certifications.
D. A certification audit is managed by a central authority.
Show Answer
Correct Answer: A
Explanation:
A formal certification is issued against a defined standard, making its criteria more consistent and verifiable than a partner’s self-attestation. Certification audits are not necessarily managed by a central authority. Sources: https://fractionalciso.com/soc-2-certification

Question 37

A company in a regulated industry experiences a data breach after an employee clicks on an email phishing link and enters credentials, leading to the exposure of sensitive information. Which of the following should the company do to prevent future attacks? (Choose two.)

A. Deploy a NAC.
B. Implement deep packet inspection.
C. Establish password complexity requirements.
D. Implement a WAF.
E. Enforce multifactor authentication.
F. Create a security awareness training program.
Show Answer
Correct Answer: E, F
Explanation:
Security awareness training helps employees recognize and avoid phishing links. Multifactor authentication reduces the risk that stolen credentials alone will allow an attacker to access sensitive information. Password complexity does not help when a valid password is disclosed. Sources: https://www.mapletech.co.uk/blog/what-to-do-if-an-employee-clicks-a-phishing-link https://www.forbes.com/councils/forbesbusinesscouncil/2022/03/18/how-to-prevent-accidental-data-exposure-within-your-company

Question 38

A developer used their workstation to generate keys that are used to secure a mission-critical application. A security engineer needs to reduce the risk of unauthorized disclosure of keying material. Which of the following is the best way to increase the security of the process?

A. HSM
B. SED
C. FDE
D. TPM
Show Answer
Correct Answer: A
Explanation:
An HSM is designed to securely generate, store, and manage cryptographic keys, keeping keying material protected from exposure on the workstation. SED and FDE protect data at rest, while a TPM primarily supports platform security and key operations rather than serving as the best dedicated key-management solution.

Question 39

During a penetration test, several users report that certain fileshares on the network could not be accessed. An analyst reviews the network traffic and detects a high number of packets associated with LLMNR and SMB that are being redirected to the penetration tester’s computer. Which of the following attacks is causing the issue?

A. SMB brute-force
B. Directory fuzzing
C. NTLM relay
D. Network poisoning
Show Answer
Correct Answer: D
Explanation:
This is LLMNR poisoning: the tester sends misleading name-resolution responses that redirect SMB traffic to their computer, disrupting access to the fileshares. NTLM relay may be a related follow-on technique, but the described traffic redirection is network poisoning.

Question 40

A security consultant recommends that a solution be deployed to increase awareness of APTs throughout the IT and ОТ environments. The consultant's requirements state that the solution must: • Be capable of collecting data from both ОТ and IT protocols. • Operate within new microsegmented and air-gapped network architecture • Provide both correlation of events and retention of raw log data and incidents • Integrate with the ITSM platform and employee paging system Which of the following solutions best meets these requirements?

A. SASE deployment with an Always On VPN
B. A next-generation firewall with intrusion prevention services
C. A vulnerability scanner with agentless scanning
D. SIEM with remote collectors
Show Answer
Correct Answer: D
Explanation:
A SIEM with remote collectors can gather logs and telemetry from IT and OT protocols across segmented or air-gapped networks, then correlate events and retain raw logs and incident records. SIEM platforms commonly integrate with ITSM and paging systems. The other options do not provide this combination of centralized security-event correlation and log retention.

$19

Get all 400 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.