CASP PRACTICE EXAM 1 QUESTIONS
AND ANSWERS WITH COMPLETE
SOLUTIONS 100% CORRECT RATED A+
Question 1: A group of employees within your company has asked for
authorization to install digital certificates provided by an external third party.
According to corporate security guidelines, you are required to confirm that these
certificates remain valid and have not been canceled before granting approval.
Which of the following methods can you use to inspect the revocation status?
(Select all that apply.)
A. CRL
B. OCSP
C. DNSSEC
D. DRM
Answer: ✔✔ A. CRL, B. OCSP
Explanation: To determine if a digital certificate has been revoked before its
scheduled expiration date, you can consult a Certificate Revocation List (CRL) or
utilize the Online Certificate Status Protocol (OCSP), depending on the architecture
of the public key infrastructure (PKI) in use.
Question 2: Your corporate network perimeter is protected by a firewall and an
Intrusion Detection System (IDS). Recently, the IDS triggered a high-priority alert
indicating that active SSL sessions are being targeted by a legacy exploit
specifically designed to abuse SSLv2. Because your web server handles financial
transactions, it must maintain robust encryption. What action should you take to
ensure this specific vulnerability can no longer be exploited?
A. Create a rule to block SSLv2 traffic directly on the perimeter firewall.
B. Restrict SSLv2 traffic natively at the web server level.
C. Disable SSLv2 entirely and ensure at least SSLv3 (or newer TLS protocols) is
enabled on the web server.
,D. Apply the most recent security patches and software updates to the web server
operating system.
Answer: ✔✔ C. Disable SSLv2 and enable SSLv3 on the web server.
Question 2: Your corporate network perimeter is protected by a firewall and an
Intrusion Detection System (IDS). Recently, the IDS triggered a high-priority alert
indicating that active SSL sessions are being targeted by a legacy exploit
specifically designed to abuse SSLv2. Because your web server handles financial
transactions, it must maintain robust encryption. What action should you take to
ensure this specific vulnerability can no longer be exploited?
A. Create a rule to block SSLv2 traffic directly on the perimeter firewall.
B. Restrict SSLv2 traffic natively at the web server level.
C. Disable SSLv2 entirely and ensure at least SSLv3 (or newer TLS protocols) is
enabled on the web server.
D. Apply the most recent security patches and software updates to the web server
operating system.
Answer: ✔✔ C. Disable SSLv2 and enable SSLv3 on the web server.
Explanation: You should disable SSLv2 and enable SSLv3 on the web server. This
will prevent the use of SSLv2, which is the problem.
The research department for your company needs to carry out a web conference
with a third party. The manager of the research department has requested that you
ensure that the web conference is encrypted because of the sensitive nature of the
topic that will be discussed. Which of the following should you deploy?
,A. SSL
B. SET
C. IPsec
D. RC4 -ANSWER ✔✔Answer: D
Explanation: RC4 is a stream-based cipher and could be used to encrypt web
conference traffic.
Your company has recently decided to merge with another company. Each
company has its own Internet PKI that deploys certificates to users within that
network. You have been asked to deploy a solution that allows each company to
trust the other's certificates. What should you do?
A. Issue a policy certificate accepting both trust paths.
B. Deploy a new PKI for all users and import the current user certificates to the new
PKI.
C. Use a cross-certification certificate.
D. Add the root certificate to both of the root certification authorities (CAs). -
ANSWER ✔✔Answer: C
, Explanation: You should use a cross-certification certificate to ensure that each
company trusts the other company's certificates.
Your company has a single, centralized web-based retail sales system. Orders come
in 12 hours per day, 364 days per year. Sales average $500,000 per day. Attacks
against the retail sales system occur on a daily basis.
For the retail sales system, there is a 1% chance of a hacker bringing the system
down. The mean time to restore the system is 6 hours. What is the ALE for this
system?
A. $912,500
B. $250,000
C. $500,000
D. $910,000 -ANSWER ✔✔Answer: D
Explanation: The annualized loss expectancy (ALE) for the system is $910,000.
The asset value (AV) is $500,000. The exposure factor (EF) is 0.5 (6 hours/12
hours).
Single loss expectancy (SLE) = AV × EF = $500,000 × 0.5 = $250,000
Annualized rate of occurrence (ARO) = 0.01 × 364 = 3.64
AND ANSWERS WITH COMPLETE
SOLUTIONS 100% CORRECT RATED A+
Question 1: A group of employees within your company has asked for
authorization to install digital certificates provided by an external third party.
According to corporate security guidelines, you are required to confirm that these
certificates remain valid and have not been canceled before granting approval.
Which of the following methods can you use to inspect the revocation status?
(Select all that apply.)
A. CRL
B. OCSP
C. DNSSEC
D. DRM
Answer: ✔✔ A. CRL, B. OCSP
Explanation: To determine if a digital certificate has been revoked before its
scheduled expiration date, you can consult a Certificate Revocation List (CRL) or
utilize the Online Certificate Status Protocol (OCSP), depending on the architecture
of the public key infrastructure (PKI) in use.
Question 2: Your corporate network perimeter is protected by a firewall and an
Intrusion Detection System (IDS). Recently, the IDS triggered a high-priority alert
indicating that active SSL sessions are being targeted by a legacy exploit
specifically designed to abuse SSLv2. Because your web server handles financial
transactions, it must maintain robust encryption. What action should you take to
ensure this specific vulnerability can no longer be exploited?
A. Create a rule to block SSLv2 traffic directly on the perimeter firewall.
B. Restrict SSLv2 traffic natively at the web server level.
C. Disable SSLv2 entirely and ensure at least SSLv3 (or newer TLS protocols) is
enabled on the web server.
,D. Apply the most recent security patches and software updates to the web server
operating system.
Answer: ✔✔ C. Disable SSLv2 and enable SSLv3 on the web server.
Question 2: Your corporate network perimeter is protected by a firewall and an
Intrusion Detection System (IDS). Recently, the IDS triggered a high-priority alert
indicating that active SSL sessions are being targeted by a legacy exploit
specifically designed to abuse SSLv2. Because your web server handles financial
transactions, it must maintain robust encryption. What action should you take to
ensure this specific vulnerability can no longer be exploited?
A. Create a rule to block SSLv2 traffic directly on the perimeter firewall.
B. Restrict SSLv2 traffic natively at the web server level.
C. Disable SSLv2 entirely and ensure at least SSLv3 (or newer TLS protocols) is
enabled on the web server.
D. Apply the most recent security patches and software updates to the web server
operating system.
Answer: ✔✔ C. Disable SSLv2 and enable SSLv3 on the web server.
Explanation: You should disable SSLv2 and enable SSLv3 on the web server. This
will prevent the use of SSLv2, which is the problem.
The research department for your company needs to carry out a web conference
with a third party. The manager of the research department has requested that you
ensure that the web conference is encrypted because of the sensitive nature of the
topic that will be discussed. Which of the following should you deploy?
,A. SSL
B. SET
C. IPsec
D. RC4 -ANSWER ✔✔Answer: D
Explanation: RC4 is a stream-based cipher and could be used to encrypt web
conference traffic.
Your company has recently decided to merge with another company. Each
company has its own Internet PKI that deploys certificates to users within that
network. You have been asked to deploy a solution that allows each company to
trust the other's certificates. What should you do?
A. Issue a policy certificate accepting both trust paths.
B. Deploy a new PKI for all users and import the current user certificates to the new
PKI.
C. Use a cross-certification certificate.
D. Add the root certificate to both of the root certification authorities (CAs). -
ANSWER ✔✔Answer: C
, Explanation: You should use a cross-certification certificate to ensure that each
company trusts the other company's certificates.
Your company has a single, centralized web-based retail sales system. Orders come
in 12 hours per day, 364 days per year. Sales average $500,000 per day. Attacks
against the retail sales system occur on a daily basis.
For the retail sales system, there is a 1% chance of a hacker bringing the system
down. The mean time to restore the system is 6 hours. What is the ALE for this
system?
A. $912,500
B. $250,000
C. $500,000
D. $910,000 -ANSWER ✔✔Answer: D
Explanation: The annualized loss expectancy (ALE) for the system is $910,000.
The asset value (AV) is $500,000. The exposure factor (EF) is 0.5 (6 hours/12
hours).
Single loss expectancy (SLE) = AV × EF = $500,000 × 0.5 = $250,000
Annualized rate of occurrence (ARO) = 0.01 × 364 = 3.64