Ready to Pass Your Certification Test

Ready to guarantee a pass on the certification that will elevate your career? Visit this page to explore our catalog and get the questions and answers you need to ace the test.

CompTIA CAS-005

Custom view settings

Exam contains 217 questions

Page 11 of 37
Question 61 🔥

[Governance, Risk, and Compliance (GRC)] A company recentlyexperienced aransomware attack. Although the company performssystems and data backupon a schedule that aligns with itsRPO (Recovery Point Objective) requirements, thebackup administratorcould not recovercritical systems and datafrom its ofline backups to meet the RPO. Eventually, the systems and data were restored with information that wassix months outside of RPO requirements. Which of the following actions should the company take to reduce the risk of a similar attack?

Question 62 🔥

[Governance, Risk, and Compliance (GRC)] A compliance officer isfacilitating abusiness impact analysis (BIA)and wantsbusiness unit leadersto collect meaningful dat a. Several business unit leaders want more information about the types of data the officer needs. Which of the following data types would be the most beneficial for the compliance officer?(Select two)

Question 63 🔥

[Security Operations] A company’sSIEMis designed to associate the company’sasset inventorywith user events. Given the following report: Which of thefollowing should asecurity engineer investigate firstas part of alog audit?

Question 64 🔥

[Security Operations] During a recentsecurity event, access from thenon -production environment to the production environmentenabledunauthorized usersto: Installunapproved software Makeunplanned configuration changes During theinvestigation, the following findings were identified: Several new users were added in bulkby theIAM team Additionalfirewalls and routerswere recently added Vulnerability assessmentshave been disabled formore than 30 days Theapplication allow listhas not been modified intwo weeks Logs were unavailablefor various types of traffic Endpoints have not been patchedinover ten days Which of the following actions would most likely need to be taken toensure proper monitoring?(Select two)

Question 65 🔥

[Security Architecture] An organization hires a security consultant to establish a SOC that includes athreat -modeling function. During initial activities, the consultant works with system engineers to identify antipatterns within the environment. Which of the following is most critical for the engineers to disclose to the consultant during this phase?

Question 66 🔥

[Identity and Access Management (IAM)] A security analyst is reviewing the following authentication logs: Which of thefollowing should the analyst do first?

Lorem ipsum dolor sit amet consectetur. Eget sed turpis aenean sit aenean. Integer at nam ullamcorper a.

© 2024 Exam Prepare, Inc. All Rights Reserved.