CAS-004 CompTIA Advanced Security Practitioner (CASP+)

Loading demo links...

Showing 4–6 of 15 questions

Question 4

city government's IT director was notified by the City council that the following cybersecurity requirements must be met to be awarded a large federal grant:

+ Logs for all critical devices must be retained for 365 days to enable monitoring and threat hunting.

+ All privileged user access must be tightly controlled and tracked to mitigate compromised accounts.

+ Ransomware threats and zero-day vulnerabilities must be quickly identified.

Which of the following technologies would BEST satisfy these requirements? (Select THREE).

Select all that apply, then click Submit answer.

  • Endpoint protection

  • Log aggregator
    Log aggregator: A log aggregator is a tool that collects, parses, and stores logs from various sources, such as devices, applications, servers, etc. A log aggregator can help meet the requirement of retaining logs for 365 days by providing a centralized and scalable storage solution1 .

  • Zero trust network access

  • PAM
    PAM: PAM stands for privileged access management. It is a technology that controls and monitors the access of privileged users (such as administrators) to critical systems and data. PAM can help meet the requirement of controlling and tracking privileged user access by enforcing policies such as least privilege, multifactor authentication, password rotation, session recording, etc. .

  • Cloud sandbox

  • SIEM
    SIEM: SIEM stands for security information and event management. It is a technology that analyzes and correlates logs from various sources to detect and respond to security incidents. SIEM can help meet the requirement of identifying ransomware threats and zero-day vulnerabilities by providing real-time alerts, threat intelligence feeds, incident response workflows, etc. .

  • NGFW

Question 5

An auditor needs to scan documents at rest for sensitive text. These documents contain both text and Images. Which of the following software functionalities must be enabled in the DLP solution for the auditor to be able to fully read these documents? (Select TWO).

Select all that apply, then click Submit answer.

  • Document interpolation

  • Regular expression pattern matching

  • Optical character recognition functionality

  • Baseline image matching

  • Advanced rasterization

  • Watermarking

Question 6

A municipal department receives telemetry data from a third-party provider The server collecting telemetry sits in the municipal departments screened network and accepts connections from the third party over HTTPS. The daemon has a code execution vulnerability from a lack of input sanitization of out-of-bound messages, and therefore, the cybersecurity engineers would like to Implement nsk mitigations. Which of the following actions, if combined, would BEST prevent exploitation of this vulnerability? (Select TWO).

Select all that apply, then click Submit answer.

  • Implementing a TLS inspection proxy on-path to enable monitoring and policy enforcement

  • Creating a Linux namespace on the telemetry server and adding to it the servicing HTTP daemon

  • Installing and configuring filesystem integrity monitoring service on the telemetry server

  • Implementing an EDR and alert on Identified privilege escalation attempts to the SIEM

  • Subscribing to a UTM service that enforces privacy controls between the internal network and the screened subnet

  • Using the published data schema to monitor and block off nominal telemetry messages