TEST BANK| D488 CYBERSECURITY ARCHITECTURE
AND ENGINEERING (CASP+) FINAL EXAM PREP
WITH COMPLETE 1000+ REAL EXAM QUESTIONS
AND CORRECT VERIFIED ANSWERS/ ALREADY
GRADED A+ (MOST RECENT!!)
An IT organization is implementing a hybrid cloud deployment. Users
should be able to sign in to all corporate resources using their email
addresses as their usernames, regardless of whether they are accessing
an application on-premises or in the cloud.
Which solution meets this requirement?
A) JSON Web Token (JWT)
B) Trusted Platform Module (TPM)
C) Single sign-on (SSO)
D) Internet Protocol Security (IPsec) -Correct Answer- C) Single sign-on
(SSO)
An IT team is preparing the network for a hybrid cloud deployment. A
security analyst recently discovered that the firmware of a router in the
core data center has been compromised. According to the analyst, the
attack occurred over a year ago without being detected.
Which type of threat actor is the most likely cause of the attack?
A) Competitor
B) Hacktivist
pg. 1
,C) Advanced persistent threat
D) Novice hacker -Correct Answer- C) Advanced persistent threat
The security operations center (SOC) team just received a notification
that multiple vulnerabilities are present in the codebase of a corporate
application.
Which threat type is most likely in this scenario?
A) Advanced persistent threat
B) Insider threat
C) Supply chain
D) Organized crime -Correct Answer- C) Supply chain
The security operations center (SOC) team for a global company is
planning an initiative to defend against security breaches. Leadership
wants the team to monitor for threats against the organization's data,
credentials, and brand reputation by scanning networks that can not be
accessed via search engines.
Which type of network should be scanned based on the requirements?
A) Wireless fidelity
B) Intranet
C) Deep web
D) Supervisory control and data acquisition -Correct Answer- C) Deep
web
pg. 2
,A company operates a customer service call center with over one
hundred agents taking inbound sales calls. After a recent security breach,
the security team believes that one or more agents have been stealing
customer credit card details.
Which solution will defend against this issue?
A) Security information and event management (SIEM)
B) File integrity monitoring (FIM)
C) Data loss prevention (DLP)
D) Intrusion detection system (IDS) -Correct Answer- C) Data loss
prevention (DLP)
The security team has noticed that several endpoints on the network
have been infected with malware. Leadership has tasked the security
team with identifying these attacks in the future.
Which solution will notify the team automatically in the event of future
malware variants invading the network?
A) Security information and event management (SIEM) alerts
B) Data loss prevention (DLP) alerts
C) Antivirus alerts
D) Syslog alerts -Correct Answer- C) Antivirus alerts
An engineer has noticed a degradation in system performance and alerts
regarding high central processing unit (CPU) usage on multiple virtual
machines in the environment. Further investigation shows that several
unknown processes are running on the affected systems.
pg. 3
, What is the explanation for the degradation in system performance and
alerts regarding high central processing unit (CPU) usage?
A) Misconfigured firewall
B) Overly permissive web application firewall (WAF) rules
C) Outdated anti-malware signatures
D) Incorrect file permissions -Correct Answer- C) Outdated anti-
malware signatures
A financial services company has experienced several incidents of data
breaches in recent months. The company has analyzed the indicators of
compromise and determined that the data breaches were caused by
insider threats. The company has decided to implement hardening
techniques and endpoint security controls to mitigate the risk.
What should be used to prevent data breaches caused by insider threats
based on the indicators of compromise?
A) Network monitoring
B) Intrusion detection systems (IDS)
C) Data loss prevention (DLP)
D) Access control systems (ACS) -Correct Answer- C) Data loss
prevention (DLP)
A company is concerned about the security of its network and wants to
implement a control that will allow only preapproved software to run on
its endpoints.
Which control should the company implement to achieve this goal?
pg. 4