CASP ACTUAL PRACTICE TEST BANK FEDVTE EXAM 1& 2
NEWEST VERSION WITH UPDATED QUESTIONS AND
CORRECT DETAILED ANSWERS \\COMPLETE EXAM WITH
VERIFIED ANSWERS |||GRADED A+
The web development team Answer: B
has a new application that
Explanation: HTTP interceptors are tools that can be used to
needs to be assessed from
introduce invalid input to see if the application performs proper
a security standpoint. When input validation.
the third-party testing team
presents its test cases, it
mentions that an HTTP
interceptor is one of the
tools it will utilize. Which of
the following issues would
this be most suitable to test
for?
A. open ports
B. input validation of a form
C. access control
D. performance under stress
/ 1/142
,4/27/25, 1:35 PM CASP Practice Exam 1 &2
Your company has recently Answer: B
purchased a new web
server that will be customer Explanation: To calculate return on investment, you
facing. Currently no security must first calculate the percentage of the asset
controls are deployed on value that is covered by the solution:
the web server. During risk
analysis, it was determined $250,000 × .9 = $225,000
that the cost of any web
ROI = Modified asset value - Control cost = $225,000 - $25,000 =
server compromise would $200,000
be
$250,000. You deploy a
security solution for
$25,000 that will provide a
90% reduction in risk.
What is the ROI for this
solution?
A. $225,000
B. $200,000
C. $25,000
D. $22,250
A new security policy Answer: C
adopted by your
organization states that you Explanation: You should monitor failed logins in a 24-
must monitor for attacks hour period. Brute-force attacks attempt to access the
that compromise user same user account using different passwords, resulting
accounts. Which of the in repeated failed logins.
following activities should
you monitor?
A. sensitive file access in a 12-
hour period
B. average throughput of
the network perimeter
/ 2/142
,4/27/25, 1:35 PM CASP Practice Exam 1 &2
C. failed logins in a 24-hour
period
D. port scans in a 24-hour
period
You have documented Answer: B
several possible solutions to
a security issue that Explanation: You should test each solution under the
occurred last week. You same conditions. This ensures that each solution will be
need to test all the possible assessed fairly in comparison to the others.
solutions to see the effect
that each has and to
determine which to deploy.
Which is the most important
guideline you should follow?
A. Maintain adequate
bandwidth while testing
each solution.
B. Test each solution
under the same
conditions.
C. Patch all lab computers
prior to testing each
solution.
D. Determine the acceptable
false-positive maximum.
/ 3/142
, 4/27/25, 1:35 PM CASP Practice Exam 1 &2
Management at your Answer: B
company has become
increasingly concerned Explanation: Of the possibilities listed, the best indicator
about botnet attacks. After of a botnet attack is an increase in TCP and UDP traffic
researching the issue, you during off-peak hours.
decide to monitor certain
conditions to help detect
whether a botnet attack is
under way. Which trend is
the best indicator of this
type of attack?
A. connection attempts
increase on Internet-
facing web servers
B. TCP and UDP traffic
increase during off- peak
hours
C. port scanning attempts
increase over a 24-hour
period
D. unsuccessful logins
increase during peak hours
/ 4/142