{"id":21987,"date":"2026-09-25T10:23:17","date_gmt":"2026-09-25T10:23:17","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21987"},"modified":"2026-09-25T10:23:17","modified_gmt":"2026-09-25T10:23:17","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 21<\/b><\/h3>\n<p><b>Which security principle ensures that users receive only the permissions required to perform their jobs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits users, applications, and systems to only the permissions necessary for authorized tasks. This principle reduces the potential damage caused by compromised accounts, malicious insiders, or accidental misuse. Organizations can implement least privilege through role-based access controls, privileged access management, periodic access reviews, and just-in-time privileges. Permissions should also be removed when responsibilities change. Granting broad administrative access simply for convenience increases the attack surface and can make security incidents more difficult to contain and investigate.<\/span><\/p>\n<h3><b>Question 22<\/b><\/h3>\n<p><b>A security architect is reviewing a third-party service provider. Which document is MOST useful for defining required security controls and responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service-level agreement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceptable use policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident ticket<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network diagram<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service-level agreement (SLA) can define specific service expectations, security requirements, availability targets, responsibilities, reporting requirements, and remediation expectations between an organization and a provider. Depending on the arrangement, security requirements may also appear in contracts, data processing agreements, or security addenda. An acceptable use policy primarily governs how users may use organizational resources. An incident ticket records a specific issue, while a network diagram describes connectivity. Third-party agreements should clearly establish security responsibilities before sensitive services or information are entrusted to a provider.<\/span><\/p>\n<h3><b>Question 23<\/b><\/h3>\n<p><b>Which technology is commonly used to provide centralized privileged account management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PAM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged access management (PAM) helps organizations control, monitor, and secure accounts with elevated permissions. PAM solutions can store privileged credentials securely, enforce approval workflows, rotate passwords, record privileged sessions, and provide temporary access when needed. These capabilities reduce the exposure associated with permanent administrative privileges. DNS resolves names, RAID provides storage redundancy, and DHCP provides network configuration information. A mature PAM implementation should also integrate with identity management, multifactor authentication, logging, and access review processes to improve accountability for privileged activity.<\/span><\/p>\n<h3><b>Question 24<\/b><\/h3>\n<p><b>An organization needs to prove that a digital document was not altered after being signed. Which security mechanism is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A digital signature can provide integrity and authentication for a digitally signed document. The signature is generated using the signer&#8217;s private key and can be verified using the corresponding public key. If the document changes after signing, signature verification should fail. Digital signatures can also support nonrepudiation when implemented within an appropriate trust and legal framework. Compression reduces data size, NAT translates network addresses, and load balancing distributes traffic. None of these mechanisms directly provides cryptographic assurance that signed content has remained unchanged.<\/span><\/p>\n<h3><b>Question 25<\/b><\/h3>\n<p><b>What is the PRIMARY purpose of threat modeling?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase storage capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify potential threats and design appropriate mitigations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace all vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Improve employee attendance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling identifies potential threats, attack paths, trust boundaries, valuable assets, and weaknesses during system or application design. Security teams can use the results to prioritize mitigations before systems are deployed. Common approaches examine threats against data flows, components, identities, and trust relationships. Threat modeling does not replace vulnerability scanning because the two activities serve different purposes. Vulnerability scanning identifies technical weaknesses, while threat modeling considers how systems could be attacked and what protections should be incorporated into the architecture.<\/span><\/p>\n<h3><b>Question 26<\/b><\/h3>\n<p><b>A company wants to detect suspicious activity by analyzing normal user behavior and identifying deviations. Which capability BEST supports this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Behavioral analytics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk defragmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Behavioral analytics establishes or evaluates patterns of normal activity and identifies deviations that may indicate compromise, misuse, or other suspicious behavior. User and entity behavior analytics (UEBA) can examine factors such as login locations, access times, resource usage, and unusual administrative actions. Behavioral analytics can complement traditional signature-based security controls because previously unknown or account-based threats may not match known indicators. The results should be evaluated in context because unusual activity is not automatically malicious and may require investigation before a response is initiated.<\/span><\/p>\n<h3><b>Question 27<\/b><\/h3>\n<p><b>Which control provides an additional authentication factor beyond a user&#8217;s password?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MFA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication (MFA) requires users to provide two or more authentication factors from different categories, such as something they know, something they have, or something they are. MFA can significantly reduce the impact of stolen passwords because possession of the password alone is insufficient for authentication. Common implementations include authenticator applications, hardware security keys, smart cards, and biometrics. MFA should be applied especially to privileged accounts, remote access, and sensitive applications. Organizations should also maintain secure recovery processes so attackers cannot bypass MFA through account recovery.<\/span><\/p>\n<h3><b>Question 28<\/b><\/h3>\n<p><b>A security team is evaluating the potential impact of a ransomware attack on critical business operations. Which process should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Code compilation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate enrollment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A business impact analysis (BIA) identifies critical business functions and evaluates the consequences of disruptions. For ransomware scenarios, a BIA can help determine which systems are essential, how long services can remain unavailable, what dependencies exist, and what recovery requirements apply. The findings support decisions about recovery priorities, redundancy, backup strategies, and continuity planning. Code compilation and certificate enrollment address unrelated technical processes, while port scanning identifies network services. A BIA should involve business stakeholders because technical teams alone may not understand every operational dependency.<\/span><\/p>\n<h3><b>Question 29<\/b><\/h3>\n<p><b>Which security assessment is designed to simulate the actions of a real attacker?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A penetration test uses controlled techniques to simulate attacks against systems, applications, networks, or other defined targets. Testers attempt to exploit vulnerabilities and demonstrate potential attack paths while operating within an approved scope. A vulnerability scan generally identifies and reports potential weaknesses without necessarily exploiting them. Asset inventories identify organizational resources, while configuration backups preserve system settings. Penetration testing should have clearly documented authorization, scope, rules of engagement, testing windows, and reporting requirements to prevent unnecessary disruption to business operations.<\/span><\/p>\n<h3><b>Question 30<\/b><\/h3>\n<p><b>An organization wants to reduce the risk of a compromised endpoint accessing sensitive servers. Which architecture is MOST effective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation separates systems into controlled security zones and limits communication between them. If an endpoint becomes compromised, segmentation can restrict its ability to reach sensitive servers or other high-value systems. Firewalls, access control lists, microsegmentation, and identity-aware policies can enforce these restrictions. A flat network generally provides broader connectivity and can make lateral movement easier. Shared administrator accounts and unrestricted routing can further increase risk. Segmentation should be based on business requirements, data sensitivity, trust relationships, and documented communication flows.<\/span><\/p>\n<h3><b>Question 31<\/b><\/h3>\n<p><b>Which control is MOST useful for detecting unauthorized changes to critical system files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk formatting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring (FIM) detects changes to monitored files, directories, and configurations. It can compare current states against known-good baselines and alert security teams when unexpected modifications occur. FIM is useful for detecting unauthorized changes to operating system files, application configurations, security settings, and other sensitive resources. Alerts should be investigated because legitimate software updates can also modify protected files. Load balancing, NAT, and disk formatting serve different infrastructure purposes and do not provide equivalent change-detection capabilities.<\/span><\/p>\n<h3><b>Question 32<\/b><\/h3>\n<p><b>A company wants to ensure that two administrators cannot independently approve and execute the same high-risk transaction. Which principle applies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elasticity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities among multiple individuals or roles so that one person cannot complete a high-risk process alone. This reduces opportunities for fraud, abuse, and unauthorized changes. For example, one administrator might request a privileged change while another reviews and approves it. The principle is especially useful for financial processes, privileged operations, security administration, and other activities requiring strong accountability. Federation concerns identity relationships between organizations, data minimization limits unnecessary data collection, and elasticity concerns scalable resource allocation.<\/span><\/p>\n<h3><b>Question 33<\/b><\/h3>\n<p><b>Which metric defines the maximum acceptable amount of data loss measured in time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery point objective (RPO) defines how much data loss an organization can tolerate, expressed as a period of time. For example, an RPO of one hour means the organization should design recovery capabilities so that losing more than approximately one hour of data is outside the acceptable target. RTO instead defines the target time for restoring a service. MTTR measures repair or recovery performance, while an SLA defines agreed service expectations. RPO requirements directly influence backup frequency, replication, and recovery architecture.<\/span><\/p>\n<h3><b>Question 34<\/b><\/h3>\n<p><b>A security team wants to identify vulnerabilities in an externally exposed web application without actively exploiting them. Which activity is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Destructive testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning uses automated tools to identify known weaknesses, insecure configurations, exposed services, and other potential security issues. It is generally less intrusive than an authorized penetration test because the objective is primarily identification rather than demonstrating exploitation. Scanning should be configured carefully to avoid excessive traffic or unintended disruption. Results should be validated because automated scanners can produce false positives or miss context-specific vulnerabilities. Security teams should prioritize findings according to severity, exposure, asset criticality, exploitability, and business impact.<\/span><\/p>\n<h3><b>Question 35<\/b><\/h3>\n<p><b>Which solution can help an organization enforce security policies on employee-owned mobile devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MDM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UPS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mobile device management (MDM) provides centralized capabilities for managing and securing mobile devices. Depending on the implementation, MDM can enforce encryption, screen-lock policies, application restrictions, configuration settings, remote wipe, compliance checks, and device enrollment. For bring-your-own-device environments, organizations should carefully define privacy boundaries and distinguish corporate data from personal information. RAID protects storage availability, DNS handles name resolution, and UPS provides power continuity. MDM can also integrate with identity and conditional-access controls to restrict access from devices that fail security requirements.<\/span><\/p>\n<h3><b>Question 36<\/b><\/h3>\n<p><b>A company discovers that a critical server is running an unsupported operating system. What is the MOST appropriate security concern?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduced keyboard performance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increased exposure to unpatched vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lower monitor resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduced network bandwidth<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unsupported operating system may no longer receive security updates, vulnerability fixes, or vendor assistance. This increases the likelihood that known vulnerabilities will remain exploitable over time. The organization should assess the server&#8217;s business importance and determine whether migration, replacement, isolation, compensating controls, or another risk treatment is appropriate. Unsupported technology should not automatically remain in production simply because it continues to function. Security teams should maintain technology lifecycle records and monitor end-of-support dates so replacement planning can occur before critical systems become unsupported.<\/span><\/p>\n<h3><b>Question 37<\/b><\/h3>\n<p><b>Which mechanism can be used to verify the identity of a certificate holder?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital certificate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A digital certificate binds an identity or entity to a public key through a trusted certificate authority or another established trust model. Certificates are commonly used with TLS to authenticate servers and, in some environments, clients. During certificate validation, systems can examine factors such as the issuer, validity period, subject or subject alternative names, and certificate chain. Compression reduces file size, VLAN tagging separates network traffic logically, and RAID mirroring provides storage redundancy. Certificate management should include issuance, renewal, revocation, and secure private-key protection.<\/span><\/p>\n<h3><b>Question 38<\/b><\/h3>\n<p><b>An organization wants to ensure security requirements are included when purchasing a new SaaS platform. What should be performed BEFORE signing the contract?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security and privacy assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove the vendor&#8217;s security requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant permanent administrator access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security and privacy assessment should be performed before adopting a SaaS platform that will process organizational information. The assessment can examine data handling, encryption, identity controls, incident response, compliance obligations, retention, subcontractors, access controls, and breach notification requirements. Contractual terms should reflect important findings and clearly assign responsibilities. Granting permanent administrator access or disabling logging creates unnecessary risk. Vendor assessment should be proportional to the sensitivity of the information and criticality of the service, with periodic reassessment after onboarding.<\/span><\/p>\n<h3><b>Question 39<\/b><\/h3>\n<p><b>Which security control can identify and block suspicious network traffic based on predefined detection rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An intrusion prevention system (IPS) monitors network traffic and can automatically block or otherwise prevent activity that matches defined malicious or suspicious patterns. IPS technologies may use signatures, behavioral techniques, protocol analysis, or other detection methods. This provides a preventive layer that differs from an intrusion detection system, which primarily generates alerts without directly blocking traffic. UPS protects against power interruptions, NAS provides network-accessible storage, and DHCP assigns network configuration. IPS rules should be tuned carefully to reduce false positives while maintaining effective threat detection.<\/span><\/p>\n<h3><b>Question 40<\/b><\/h3>\n<p><b>A company wants to preserve evidence from a compromised system for a potential investigation. Which action should be prioritized?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immediately delete temporary files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preserve evidence using a documented forensic process<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reinstall the operating system without collecting evidence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow unrestricted access to the system<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Digital evidence should be preserved using a documented forensic process that maintains integrity and supports later analysis. Investigators should follow approved procedures for collection, storage, access control, hashing, documentation, and chain of custody. Depending on the incident, volatile information may need to be collected before a system is powered down, while disk images can be acquired using appropriate forensic methods. Reinstalling or modifying the system before evidence collection can destroy valuable information. Evidence handling should also consider legal, regulatory, organizational, and investigative requirements.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 21 Which security principle ensures that users receive only the permissions required to perform their jobs? Separation of duties Least privilege Nonrepudiation Federation Correct Answer: 2 Explanation Least privilege limits users, applications, and systems to only the permissions necessary for authorized tasks. This [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21987"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21987"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21987\/revisions"}],"predecessor-version":[{"id":21988,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21987\/revisions\/21988"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}