Exam Details

  • Exam Code
    :CAS-005
  • Exam Name
    :CompTIA SecurityX
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :261 Q&As
  • Last Updated
    :Mar 31, 2025

CompTIA CompTIA Certifications CAS-005 Questions & Answers

  • Question 151:

    An audit finding reveals that a legacy platform has not retained loos for more than 30 days The platform has been segmented due to its interoperability with newer technology. As a temporary solution, the IT department changed the log retention to 120 days.

    Which of the following should the security engineer do to ensure the logs are being properly retained?

    A. Configure a scheduled task nightly to save the logs

    B. Configure event-based triggers to export the logs at a threshold.

    C. Configure the SIEM to aggregate the logs

    D. Configure a Python script to move the logs into a SQL database.

  • Question 152:

    A senior security engineer flags me following log file snippet as hawing likely facilitated an attacker's lateral movement in a recent breach:

    Which of the following solutions, if implemented, would mitigate the nsk of this issue reoccurnnp?

    A. Disabling DNS zone transfers

    B. Restricting DNS traffic to UDP'W

    C. Implementing DNS masking on internal servers

    D. Permitting only clients from internal networks to query DNS

  • Question 153:

    A company's help desk is experiencing a large number of calls from the finance department slating access issues to www bank com The security operations center reviewed the following security logs:

    Which of the following is most likely the cause of the issue?

    A. Recursive DNS resolution is failing

    B. The DNS record has been poisoned.

    C. DNS traffic is being sinkholed.

    D. The DNS was set up incorrectly.

  • Question 154:

    Which of the following best explains the importance of determining organization risk appetite when operating with a constrained budget?

    A. Risk appetite directly impacts acceptance of high-impact low-likelihood events.

    B. Organizational risk appetite varies from organization to organization

    C. Budgetary pressure drives risk mitigation planning in all companies

    D. Risk appetite directly influences which breaches are disclosed publicly

  • Question 155:

    An organization wants to implement a platform to better identify which specific assets are affected by a given vulnerability.

    Which of the following components provides the best foundation to achieve this goal?

    A. SASE

    B. CMDB

    C. SBoM

    D. SLM

  • Question 156:

    The identity and access management team is sending logs to the SIEM for continuous monitoring. The deployed log collector is forwarding logs to the SIEM. However, only false positive alerts are being generated.

    Which of the following is the most likely reason for the inaccurate alerts?

    A. The compute resources are insufficient to support the SIEM

    B. The SIEM indexes are 100 large

    C. The data is not being properly parsed

    D. The retention policy is not property configured

  • Question 157:

    A security review revealed that not all of the client proxy traffic is being captured. Which of the following architectural changes best enables the capture of traffic for analysis?

    A. Adding an additional proxy server to each segmented VLAN

    B. Setting up a reverse proxy for client logging at the gateway

    C. Configuring a span port on the perimeter firewall to ingest logs

    D. Enabling client device logging and system event auditing

  • Question 158:

    Users must accept the terms presented in a captive petal when connecting to a guest network. Recently, users have reported that they are unable to access the Internet after joining the network A network engineer observes the following:

    1.

    Users should be redirected to the captive portal.

    2.

    The Motive portal runs Tl. S 1 2

    3.

    Newer browser versions encounter security errors that cannot be bypassed

    4.

    Certain websites cause unexpected re directs

    Which of the following mow likely explains this behavior?

    A. The TLS ciphers supported by the captive portal ate deprecated

    B. Employment of the HSTS setting is proliferating rapidly.

    C. Allowed traffic rules are causing the NIPS to drop legitimate traffic

    D. An attacker is redirecting supplicants to an evil twin WLAN.

  • Question 159:

    Company A acquired Company B and needs to determine how the acquisition will impact the attack surface of the organization as a whole.

    Which of the following is the best way to achieve this goal? (Select two).

    A. Implementing DLP controls preventing sensitive data from leaving Company B's network

    B. Documenting third-party connections used by Company B

    C. Reviewing the privacy policies currently adopted by Company B

    D. Requiring data sensitivity labeling tor all files shared with Company B

    E. Forcing a password reset requiring more stringent passwords for users on Company B's network

    F. Performing an architectural review of Company B's network

  • Question 160:

    A company's security policy states that any publicly available server must be patched within 12 hours after a patch is released A recent llS zero-day vulnerability was discovered that affects all versions of the Windows Server OS:

    Which of the following hosts should a security analyst patch first once a patch is available?

    A. 1

    B. 2

    C. 3

    D. 4

    E. 5

    F. 6

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-005 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.