You can save far more time in case you utilize our CompTIA CAS-001 study guidebook. To put that another way, you dont must spend a lot time upon reading people lengthy books. Each of our CompTIA CompTIA CAS-001 dumps also contain numerous wonderful simulated questions. The simulated questions are generally merged into the CAS-001 questions along with answers of our CompTIA CAS-001 study guides. Its really convenient for you personally to get ready the exam along with our incredible CAS-001 materials. All of us make sure that you will certainly definitely achieve success so long as you put pace along with our CompTIA certification research materials. Naturally, you should possess a vast knowledge regarding the course firstly. The far more you research the CAS-001 research materials, your nearer to your destination. The actual CompTIA CAS-001 books or the eBooks are generally portable, so you can acquire them everywhere and anytime you want. You have a good access towards the CompTIA study guidebook for added assistance. We promise the buyers absolute achievement due to ultimate, authentic along with excellent supplies.

2021 Sep CAS-001 test questions

Q161. - (Topic 2) 

A security architect is seeking to outsource company server resources to a commercial cloud service provider. The provider under consideration has a reputation for poorly controlling physical access to datacenters and has been the victim of multiple social engineering attacks. The service provider regularly assigns VMs from multiple clients to the same physical resources. When conducting the final risk assessment which of the following should the security architect take into consideration? 

A. The ability to implement user training programs for the purpose of educating internal staff about the dangers of social engineering. 

B. The cost of resources required to relocate services in the event of resource exhaustion on a particular VM. 

C. The likelihood a malicious user will obtain proprietary information by gaining local access to the hypervisor platform. 

D. Annual loss expectancy resulting from social engineering attacks against the cloud service provider affecting corporate network infrastructure. 

Answer: C 


Q162. - (Topic 3) 

A security consultant is hired by a company to determine if an internally developed web application is vulnerable to attacks. The consultant spent two weeks testing the application, and determines that no vulnerabilities are present. Based on the results of the tools and tests available, which of the following statements BEST reflects the security status of the application? 

A. The company’s software lifecycle management improved the security of the application. 

B. There are no vulnerabilities in the application. 

C. The company should deploy a web application firewall to ensure extra security. 

D. There are no known vulnerabilities at this time. 

Answer: D 


Q163. - (Topic 4) 

When generating a new key pair, a security application asks the user to move the mouse and type random characters on the keyboard. Which of the following BEST describes why this is necessary? 

A. The user needs a non-repudiation data source in order for the application to generate the key pair. 

B. The user is providing entropy so the application can use random data to create the key pair. 

C. The user is providing a diffusion point to the application to aid in creating the key pair. 

D. The application is requesting perfect forward secrecy from the user in order to create the key pair. 

Answer: B 


Q164. - (Topic 2) 

An organization recently upgraded its wireless infrastructure to support WPA2 and requires all clients to use this method. After the upgrade, several critical wireless clients fail to connect because they are only WEP compliant. For the foreseeable future, none of the affected clients have an upgrade path to put them into compliance with the WPA2 requirement. Which of the following provides the MOST secure method of integrating the non-compliant clients into the network? 

A. Create a separate SSID and WEP key to support the legacy clients and enable detection of rogue APs. 

B. Create a separate SSID and WEP key on a new network segment and only allow required communication paths. 

C. Create a separate SSID and require the legacy clients to connect to the wireless network using certificate-based 802.1x. 

D. Create a separate SSID and require the use of dynamic WEP keys. 

Answer: B 


Q165. - (Topic 1) 

A security administrator has finished building a Linux server which will host multiple virtual machines through hypervisor technology. Management of the Linux server, including monitoring server performance, is achieved through a third party web enabled application installed on the Linux server. The security administrator is concerned about vulnerabilities in the web application that may allow an attacker to retrieve data from the virtual machines. 

Which of the following will BEST protect the data on the virtual machines from an attack? 

A. The security administrator must install the third party web enabled application in a chroot environment. 

B. The security administrator must install a software firewall on both the Linux server and the virtual machines. 

C. The security administrator must install anti-virus software on both the Linux server and the virtual machines. 

D. The security administrator must install the data exfiltration detection software on the perimeter firewall. 

Answer: A 


CAS-001 answers

Abreast of the times CAS-001 test engine:

Q166. - (Topic 4) 

A security administrator is tasked with implementing two-factor authentication for the company VPN. The VPN is currently configured to authenticate VPN users against a backend RADIUS server. New company policies require a second factor of authentication, and the Information Security Officer has selected PKI as the second factor. Which of the following should the security administrator configure and implement on the VPN concentrator to implement the second factor and ensure that no error messages are displayed to the user during the VPN connection? (Select TWO). 

A. The user’s certificate private key must be installed on the VPN concentrator. 

B. The CA’s certificate private key must be installed on the VPN concentrator. 

C. The user certificate private key must be signed by the CA. 

D. The VPN concentrator’s certificate private key must be signed by the CA and installed on the VPN concentrator. 

E. The VPN concentrator’s certificate private key must be installed on the VPN concentrator. 

F. The CA’s certificate public key must be installed on the VPN concentrator. 

Answer: E,F 


Q167. - (Topic 5) 

The Chief Information Security Officer (CISO) at a company knows that many users store business documents on public cloud-based storage; and realizes this is a risk to the company. In response, the CISO implements a mandatory training course in which all employees are instructed on the proper use of cloud-based storage. Which of the following risk strategies did the CISO implement? 

A. Avoid 

B. Accept 

C. Mitigate 

D. Transfer 

Answer: C 


Q168. - (Topic 1) 

The security administrator has been tasked with providing a solution that would not only eliminate the need for physical desktops, but would also centralize the location of all desktop applications, without losing physical control of any network devices. Which of the following would the security manager MOST likely implement? 

A. VLANs 

B. VDI 

C. PaaS 

D. IaaS 

Answer: B 


Q169. - (Topic 5) 

A Chief Information Security Officer (CISO) is approached by a business unit manager who heard a report on the radio this morning about an employee at a competing firm who shipped a VPN token overseas so a fake employee could log into the corporate VPN. The CISO asks what can be done to mitigate the risk of such an incident occurring within the organization. Which of the following is the MOST cost effective way to mitigate such a risk? 

A. Require hardware tokens to be replaced on a yearly basis. 

B. Implement a biometric factor into the token response process. 

C. Force passwords to be changed every 90 days. 

D. Use PKI certificates as part of the VPN authentication process. 

Answer: B 


Q170. - (Topic 4) 

Due to a new regulatory requirement, ABC Company must now encrypt all WAN transmissions. When speaking with the network administrator, the security administrator learns that the existing routers have the minimum processing power to do the required level of encryption. Which of the following solutions minimizes the performance impact on the router? 

A. Deploy inline network encryption devices 

B. Install an SSL acceleration appliance 

C. Require all core business applications to use encryption 

D. Add an encryption module to the router and configure IPSec 

Answer: A