The actual CAS-001 software regarding Testking can verify any testee whether to grasp the CompTIA Advanced Security Practitioner information strongly as well as actual answers. The actual Testking CAS-001 items are consist of numerous choose. Applicant can pick different package deal goods for your CAS-001 pdf file or CAS-001 vce software according to their very own understand with the CAS-001 circumstance.

2021 Aug CAS-001 exam fees

Q201. - (Topic 1) 

Driven mainly by cost, many companies outsource computing jobs which require a large amount of processor cycles over a short duration to cloud providers. This allows the company to avoid a large investment in computing resources which will only be used for a short time. 

Assuming the provisioned resources are dedicated to a single company, which of the following is the MAIN vulnerability associated with on-demand provisioning? 

A. Traces of proprietary data which can remain on the virtual machine and be exploited 

B. Remnants of network data from prior customers on the physical servers during a compute job 

C. Exposure of proprietary data when in-transit to the cloud provider through IPSec tunnels 

D. Failure of the de-provisioning mechanism resulting in excessive charges for the resources 

Answer: A 


Q202. - (Topic 3) 

A company runs large computing jobs only during the overnight hours. To minimize the amount of capital investment in equipment, the company relies on the elastic computing services of a major cloud computing vendor. Because the virtual resources are created and destroyed on the fly across a large pool of shared resources, the company never knows which specific hardware platforms will be used from night to night. Which of the following presents the MOST risk to confidentiality in this scenario? 

A. Loss of physical control of the servers 

B. Distribution of the job to multiple data centers 

C. Network transmission of cryptographic keys 

D. Data scraped from the hardware platforms 

Answer: D 


Q203. - (Topic 3) 

A financial company implements end-to-end encryption via SSL in the DMZ, and only IPSec in transport mode with AH enabled and ESP disabled throughout the internal network. The company has hired a security consultant to analyze the network infrastructure and provide a solution for intrusion prevention. Which of the following recommendations should the consultant provide to the security administrator? 

A. Switch to TLS in the DMZ. Implement NIPS on the internal network, and HIPS on the DMZ. 

B. Switch IPSec to tunnel mode. Implement HIPS on the internal network, and NIPS on the DMZ. 

C. Disable AH. Enable ESP on the internal network, and use NIPS on both networks. 

D. Enable ESP on the internal network, and place NIPS on both networks. 

Answer: A 


Q204. - (Topic 2) 

At one time, security architecture best practices led to networks with a limited number (1-3) of network access points. This restriction allowed for the concentration of security resources and resulted in a well defined attack surface. The introduction of wireless networks, highly portable network devices, and cloud service providers has rendered the network boundary and attack surface increasingly porous. This evolution of the security architecture has led to which of the following? 

A. Increased security capabilities, the same amount of security risks and a higher TCO but a smaller corporate datacenter on average. 

B. Increased business capabilities and increased security risks with a lower TCO and smaller physical footprint on the corporate network. 

C. Increased business capabilities and increased security risks with a higher TCO and a larger physical footprint. 

D. Decreased business capabilities and increased security risks with a lower TCO and increased logical footprint due to virtualization. 

Answer: C 


Q205. - (Topic 3) 

In single sign-on, the secondary domain needs to trust the primary domain to do which of the following? (Select TWO). 

A. Correctly assert the identity and authorization credentials of the end user. 

B. Correctly assert the authentication and authorization credentials of the end user. 

C. Protect the authentication credentials used to verify the end user identity to the secondary domain for unauthorized use. 

D. Protect the authentication credentials used to verify the end user identity to the secondary domain for authorized use. 

E. Protect the accounting credentials used to verify the end user identity to the secondary domain for unauthorized use. 

F. Correctly assert the identity and authentication credentials of the end user. 

Answer: D,F 


CAS-001 free practice test

Renewal CAS-001 book:

Q206. - (Topic 1) 

A certain script was recently altered by the author to meet certain security requirements, and needs to be executed on several critical servers. Which of the following describes the process of ensuring that the script being used was not altered by anyone other than the author? 

A. Digital encryption 

B. Digital signing 

C. Password entropy 

D. Code signing 

Answer: D 


Q207. - (Topic 1) 

A system designer needs to factor in CIA requirements for a new SAN. Which of the CIA requirements is BEST met by multipathing? 

A. Confidentiality 

B. Authentication 

C. Integrity 

D. Availability 

Answer: D 


Q208. - (Topic 2) 

..... 

Company A is trying to implement controls to reduce costs and time spent on litigation. 

To accomplish this, Company A has established several goals: 

Prevent data breaches from lost/stolen assets 

Reduce time to fulfill e-discovery requests 

Prevent PII from leaving the network 

Lessen the network perimeter attack surface 

Reduce internal fraud 

Which of the following solutions accomplishes the MOST of these goals? 

A. Implement separation of duties; enable full encryption on USB devices and cell phones, allow cell phones to remotely connect to e-mail and network VPN, enforce a 90 day data retention policy. 

B. Eliminate VPN access from remote devices. Restrict junior administrators to read-only shell access on network devices. Install virus scanning and SPAM filtering. Harden all servers with trusted OS extensions. 

C. Create a change control process with stakeholder review board, implement separation of duties and mandatory vacation, create regular SAN snapshots, enable GPS tracking on all cell phones and laptops, and fully encrypt all email in transport. 

D. Implement outgoing mail sanitation and incoming SPAM filtering. Allow VPN for mobile devices; cross train managers in multiple disciplines, ensure all corporate USB drives are provided by Company A and de-duplicate all server storage. 

Answer: A 


Q209. - (Topic 3) 

Several business units have requested the ability to use collaborative web-based meeting places with third party vendors. Generally these require user registration, installation of client-based ActiveX or Java applets, and also the ability for the user to share their desktop in read-only or read-write mode. In order to ensure that information security is not compromised, which of the following controls is BEST suited to this situation? 

A. Disallow the use of web-based meetings as this could lead to vulnerable client-side components being installed, or a malicious third party gaining read-write control over an internal workstation. 

B. Hire an outside consultant firm to perform both a quantitative and a qualitative risk-based assessment. Based on the outcomes, if any risks are identified then do not allow web-based meetings. If no risks are identified then go forward and allow for these meetings to occur. 

C. Allow the use of web-based meetings, but put controls in place to ensure that the use of these meetings is logged and tracked. 

D. Evaluate several meeting providers. Ensure that client-side components do not introduce undue security risks. Ensure that the read-write desktop mode can either be prevented or strongly audited. 

Answer: D 


Q210. - (Topic 3) 

Due to cost and implementation time pressures, a security architect has allowed a NAS to be used instead of a SAN for a non-critical, low volume database. Which of the following would make a NAS unsuitable for a business critical, high volume database application that required a high degree of data confidentiality and data availability? (Select THREE). 

A. File level transfer of data 

B. Zoning and LUN security 

C. Block level transfer of data 

D. Multipath 

E. Broadcast storms 

F. File level encryption 

G. Latency 

Answer: A,E,G