Comptia

CAS-005 Free Practice Questions — Page 8

Question 71

A security engineer wants to enhance the security posture of end-user systems in a zero trust environment. Given the following requirements: • Reduce the ability for potentially compromised endpoints to contact C2 infrastructure. • Track the requests that the malware makes to the IPs. • Avoid the download of additional payloads. Which of the following should the engineer deploy to meet these requirements?

A. DNS sinkholing
B. Browser isolation
C. Zone transfer protection
D. HIDS
Show Answer
Correct Answer: A
Explanation:
DNS sinkholing redirects requests for known malicious domains to a controlled sinkhole address instead of the C2 server. This limits endpoint communication with C2, lets the engineer monitor attempted requests, and prevents the endpoint from reaching the real server to download additional payloads.

Question 72

An organization is developing an AI-enabled digital worker to help employees complete common tasks, such as template development, editing, research, and scheduling. As part of the AI workload, the organization wants to implement guardrails within the platform. Which of the following should the company do to secure the AI environment?

A. Limit the platform's abilities to only non-sensitive functions.
B. Enhance the training model's effectiveness.
C. Grant the system the ability to self-govern.
D. Require end-user acknowledgement of organizational policies.
Show Answer
Correct Answer: A
Explanation:
Restricting the AI platform to non-sensitive functions limits the potential impact of errors, misuse, or unauthorized actions. Improving the model or relying on user policy acknowledgements does not by itself constrain the system’s capabilities; the system should not be allowed to self-govern.

Question 73

An incident response team is analyzing malware and observes the following: • Does not execute in a sandbox • No network IoCs • No publicly known hash match • No process injection method detected Which of the following should the team do next to proceed with further analysis?

A. Use an online virus analysis tool to analyze the sample.
B. Check for an anti-virtualization code in the sample.
C. Utilize a new deployed machine to run the sample.
D. Search other internal sources for a new sample.
Show Answer
Correct Answer: B
Explanation:
Since the sample does not execute in the sandbox, check whether it detects virtualized or sandboxed environments and deliberately suppresses execution. This can explain the lack of observable behavior and guide further analysis.

Question 74

A security engineer performed a code scan that resulted in many false positives. The security engineer must find a solution that improves the quality of scanning results before application deployment. Which of the following is the best solution?

A. Limiting the tool to a specific coding language and tuning the rule set
B. Configuring branch protection rules and dependency checks
C. Using an application vulnerability scanner to identify coding flaws in production
D. Performing updates on code libraries before code development
Show Answer
Correct Answer: A
Explanation:
Restricting the scan to the application's relevant programming language and tuning the rules reduces irrelevant findings, improving scan accuracy and reducing false positives before deployment.

Question 75

Which of the following enables the meaningful manipulation of encrypted data when the processor does not know the encryption key?

A. Simultaneous authentication of equals
B. Envelope encryption
C. Authenticated encryption with associated data
D. Homomorphic encryption
Show Answer
Correct Answer: D
Explanation:
Homomorphic encryption supports computations on ciphertext, allowing a processor to manipulate encrypted data without knowing the encryption key. The authorized key holder can decrypt the result afterward.

Question 76

A security analyst discovered requests associated with IP addresses known for both legitimate and bot-related traffic. Which of the following should the analyst use to determine whether the requests are malicious?

A. User-agent string
B. Byte length of the request
C. Web application headers
D. HTML encoding field
Show Answer
Correct Answer: A
Explanation:
The User-Agent string identifies the client software making the request and can help distinguish legitimate browser traffic from suspicious or known bot patterns. It is not conclusive on its own because it can be spoofed, but it is the best option listed.

Question 77

An organization is required to: • Respond to internal and external inquiries in a timely manner. • Provide transparency. • Comply with regulatory requirements. The organization has not experienced any reportable breaches but wants to be prepared if a breach occurs in the future. Which of the following is the best way for the organization to prepare?

A. Outsourcing the handling of necessary regulatory filings to an external consultant
B. Integrating automated response mechanisms into the data subject access request process
C. Developing communication templates that have been vetted by internal and external counsel
D. Conducting lessons-learned activities and integrating observations into the crisis management plan
Show Answer
Correct Answer: C
Explanation:
Preapproved communication templates, reviewed by counsel, enable the organization to respond quickly and consistently to internal and external inquiries after a breach while supporting transparency and regulatory compliance. The other options address narrower or post-incident activities.

Question 78

A security engineer must integrate device attestation into user authentication and authorization workflows for mobile devices. Which of the following best meets the requirements?

A. Enforcing a security boundary for all devices outside the perimeter network
B. Enabling multifactor authentication using biometrics on access attempts
C. Implementing single sign-on to centralize access control enforcement
D. Configuring device profiling for patch level and jailbreak status
Show Answer
Correct Answer: D
Explanation:
Device attestation verifies a device’s security posture—such as its patch level and whether it is jailbroken or rooted—and can use that information in authentication and authorization decisions.

Question 79

A global company with a remote workforce implemented a new VPN solution. After deploying the VPN solution to several hundred users, the help desk starts receiving reports of slow access to both internally and externally available applications. A security analyst reviews the following: VPN client routing: 0.0.0.0/0 eth1 Which of the following solutions should the analyst use to fix this issue?

A. Move the servers to a screened subnet.
B. Enable split tunneling.
C. Configure an NAC solution.
D. Implement DNS over HTTPS.
Show Answer
Correct Answer: B
Explanation:
The route 0.0.0.0/0 sends all traffic through the VPN, including traffic to public applications. This can overload the VPN and slow access. Enable split tunneling so only traffic destined for internal networks uses the VPN, while internet-bound traffic connects directly.

Question 80

A malicious actor exploited firmware vulnerabilities and used rootkits in an attack on an organization. After the organization recovered from the incident, an engineer needs to recommend a solution that reduces the likelihood of the same type of attack in the future. Which of the following is the most relevant solution?

A. Enabling software integrity checks
B. Installing self-encrypting drives
C. Implementing measured boot
D. Configuring host-based encryption
Show Answer
Correct Answer: C
Explanation:
Measured boot records cryptographic measurements of firmware and boot components in a TPM, helping detect unauthorized changes such as firmware-level rootkits and support response before the system is trusted. Encryption protects data at rest, while general software integrity checks are less specifically focused on the boot chain.

$19

Get all 400 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.