CompTIA certification preparation

CAS-005 Practice Questions

Practice exam-style questions, check your answers, and review explanations and source references where they are available.

Exam
CAS-005
Provider
CompTIA
Full set
343 questions
Last Update Check
[Security Architecture] Users are willing passwords on paper because of the number of passwords needed in an environment. Which of the following solutions is the best way to manage this situation and decrease risks?
Answer options
[Emerging Technologies and Threats] Due to locality and budget constraints, an organization’s satellite office has a lower bandwidth allocation than other offices. As a result, the local securityinfrastructure staff is assessing architectural options that will help preserve network bandwidth and increase speed to both internal and external resources while not sacrificing threat visibility. Which of the following would be the best option to implement?
Answer options
[Security Engineering and Cryptography] A developer needs toimprove the cryptographic strength of a password-storage component in a web application without completely replacing the crypto-module. Which of the following is the most appropriate technique?
Answer options
[Emerging Technologies and Threats] Which of the following AI concerns is most adequately addressed by input sanitation?
Answer options
[Security Architecture] A security analyst is reviewingsuspicious log-in activity and sees the following data in the SICM: CompTIA Security X CASP+ CAS-005 question Which of the following is the most appropriate action for the analyst to take?
Answer options
[Governance, Risk, and Compliance (GRC)] An audit finding reveals that a legacy platform has not retained loos for more than 30 days The platform has been segmented due to its interoperability with newer technology. As a temporarysolution, the IT department changed the log retention to 120 days. Which of the following should the security engineer do to ensure the logs are being properly retained?
Answer options
[Security Operations] After an incident response exercise, a security administrator reviews the following table: CompTIA Security X CASP+ CAS-005 question Which of the following should the administrator do to beat support rapid incident response in the future?
Answer options

[Security Engineering and Cryptography] Emails that the marketing department is sending to customers are pomp to the customers' spam folders. The security team is investigating the issue and discovers that the certificates used by the email server were reissued, but DNS records had not been updated. Which of the following should the security team update in order to fix this issue? (Select three.)

Answer options
[Security Architecture] A security analyst is troubleshooting the reason a specific user is having difficulty accessing company resources The analyst reviews the following information: CompTIA Security X CASP+ CAS-005 question Which of the following is most likely the cause of the issue?
Answer options
[Security Architecture] A senior security engineer flags the following log file snippet as having likely facilitated an attacker’s lateral movement in a recent breach: qry_source: 19.27.214.22 TCP/53 qry_dest: 199.105.22.13 TCP/53 qry_type: AXFR | in comptia.org ------------ directoryserver1 A 10.80.8.10 ------------directoryserver2 A 10.80.8.11 ------------ directoryserver3 A 10.80.8.12 ------------ internal-dns A 10.80.9.1 ----------- www-int A 10.80.9.3 ------------ fshare A 10.80.9.4 ------------ sip A 10.80.9.5 ------------ msn-crit-apcs A 10.81.22.33 Which of the following solutions, if implemented, would mitigate the risk of this issue reoccurring?
Answer options
Question 1 of 10

Source context

How this practice set is maintained

Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.

Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.

Scroll to Top