CAS-003 試験問題を無料オンラインアクセス
| 試験コード: | CAS-003 |
| 試験名称: | CompTIA Advanced Security Practitioner (CASP) |
| 認定資格: | CompTIA |
| 無料問題数: | 683 |
| 更新日: | 2026-08-29 |
An ICS security engineer is performing a security assessment at a bank in Chicago. The engineer reviews the following output:
Which of the following tools is the engineer using the provide this output?
An online shopping site restricts the quantity of an item each customer can order. The site generates the following code when the customer clicks the submit button.
However, customers are still able to order more man three of the item. Which of the following would a security analyst MOST likely use to investigate the issue?
A security administrator is hardening a TrustedSolaris server that processes sensitive dat a. The data owner has established the following security requirements:
The data is for internal consumption only and shall not be distributed to outside individuals The systems administrator should not have access to the data processed by the server The integrity of the kernel image is maintained Which of the following host-based security controls BEST enforce the data owner's requirements? (Choose three.)
An agency has implemented a data retention policy that requires tagging data according to type before storing it in the data repository. The policy requires all business emails be automatically deleted after two years. During an open records investigation, information was found on an employee's work computer concerning a conversation that occurred three years prior and proved damaging to the agency's reputation. Which of the following MOST likely caused the data leak?
Ann, a member of the finance department at a large corporation, has submitted a suspicious email she received to the information security team. The team was not expecting an email from Ann, and it contains a PDF file inside a ZIP compressed archive. The information security learn is not sure which files were opened. A security team member uses an air-gapped PC to open the ZIP and PDF, and it appears to be a social engineering attempt to deliver an exploit.
Which of the following would provide greater insight on the potential impact of this attempted attack?