D488 - Cybersecurity Architecture and Engineering (CASP+) Exam
An IT security team has been notified that external C) Implementing port security
contractors are using their personal laptops to gain
access to the corporate network. The team needs to
recommend a solution that will prevent unapproved
devices from accessing the network.
Which solution fulfills these requirements?
A) Implementing a demilitarized zone (DMZ)
B) Installing a hardware security module
C) Implementing port security
D) Deploying a software firewall
The chief technology officer for a small publishing C) Deploying a unified threat management (UTM) appliance
company has been tasked with improving the
company's security posture. As part of a network
upgrade, the company has decided to implement
intrusion detection, spam filtering, content filtering, and
antivirus controls. The project needs to be completed
using the least amount of infrastructure while meeting
all requirements.
Which solution fulfills these requirements?
A) Deploying an anti-spam gateway
B) Deploying a proxy server
C) Deploying a unified threat management (UTM)
appliance
D) Deploying a web application firewall (WAF)
The security team plans to deploy an intrusion C) Signature-based detection
detection system (IDS) solution to alert engineers
about inbound threats. The team already has a database
of signatures that they want the IDS solution to validate.
Which detection technique meets the requirements?
A) Intrusion detection
B) Deep packet inspection
C) Signature-based detection
D) Intrusion prevention
, D488 - Cybersecurity Architecture and Engineering (CASP+) Exam
An IT organization had a security breach after C) Implementing versioning
deploying an update to its production web servers. The
application currently goes through a manual update
process a few times per year. The security team needs
to recommend a failback option for future
deployments.
Which solution fulfills these requirements?
A) Implementing a code scanner
B) Implementing code signing
C) Implementing versioning
D) Implementing a security requirements traceability
matrix (SRTM)
A software development team is working on a new C) Code signing
mobile application that will be used by customers. The
security team must ensure that builds of the application
will be trusted by a variety of mobile devices.
Which solution fulfills these requirements?
A) Code scanning
B) Regression testing
C) Code signing
D) Continuous delivery
An IT organization recently suffered a data leak C) Digital rights management (DRM)
incident. Management has asked the security team to
implement a print blocking mechanism for all
documents stored on a corporate file share.
Which solution fulfills these requirements?
A) Virtual desktop infrastructure (VDI)
B) Remote Desktop Protocol (RDP)
C) Digital rights management (DRM)
D) Watermarking
A company has recently discovered that a competitor is C) Digital rights management (DRM)
distributing copyrighted videos produced by the in-
house marketing team. Management has asked the
security team to prevent these types of violations in the
future.
Which solution fulfills these requirements?
A) Virtual desktop infrastructure (VDI)
B) Secure Socket Shell (SSH)
C) Digital rights management (DRM)
D) Remote Desktop Protocol (RDP)
, D488 - Cybersecurity Architecture and Engineering (CASP+) Exam
A security team has been tasked with performing C) Automatically
regular vulnerability scans for a cloud-based
infrastructure.
How should these vulnerability scans be conducted
when implementing zero trust security?
A) Manually
B) Annually
C) Automatically
D) As needed
A healthcare company needs to ensure that medical C) Anonymization
researchers cannot inadvertently share protected
health information (PHI) data from medical records.
What is the best solution?
A) Encryption
B) Metadata
C) Anonymization
D) Obfuscation
A security team has been tasked with mitigating the risk C) Privileged access management (PAM)
of stolen credentials after a recent breach. The solution
must isolate the use of privileged accounts. In the
future, administrators must request access to mission-
critical services before they can perform their tasks.
What is the best solution?
A) Identity and access management (IAM)
B) Password policies
C) Privileged access management (PAM)
D) Password complexity
A global manufacturing company is moving its C) Attribute-based access control (ABAC)
applications to the cloud. The security team has been
tasked with hardening the access controls for a
corporate web application that was recently migrated.
End users should be granted access to different
features based on their locations and departments.
Which access control solution should be implemented?
A) Kerberos
B) Mandatory access control (MAC)
C) Attribute-based access control (ABAC)
D) Privileged access management (PAM)
, D488 - Cybersecurity Architecture and Engineering (CASP+) Exam
A team of developers is building a new corporate web C) Out-of-band authentication
application. The security team has stated that the
application must authenticate users through two
separate channels of communication.
Which type of authentication method should the
developers include when building the application?
A) In-band authentication
B) Kerberos
C) Out-of-band authentication
D) Challenge-Handshake Authentication Protocol
(CHAP)
An IT organization is implementing a hybrid cloud C) Single sign-on (SSO)
deployment. Users should be able to sign in to all
corporate resources using their email addresses as their
usernames, regardless of whether they are accessing an
application on-premises or in the cloud.
Which solution meets this requirement?
A) JSON Web Token (JWT)
B) Trusted Platform Module (TPM)
C) Single sign-on (SSO)
D) Internet Protocol Security (IPsec)
The security team has been tasked with implementing a C) Open Authentication (OAuth)
secure authorization protocol for its web applications.
Which of the following protocols provides the best
method for securely authenticating users and granting
access?
A) Simple network management protocol (SNMP)
B) Extensible Authentication Protocol (EAP)
C) Open Authentication (OAuth)
D) Secure Sockets Layer (SSL)
An IT team is preparing the network for a hybrid cloud C) Advanced persistent threat
deployment. A security analyst recently discovered that
the firmware of a router in the core data center has
been compromised. According to the analyst, the
attack occurred over a year ago without being
detected.
Which type of threat actor is the most likely cause of
the attack?
A) Competitor
B) Hacktivist
C) Advanced persistent threat
D) Novice hacker
An IT security team has been notified that external C) Implementing port security
contractors are using their personal laptops to gain
access to the corporate network. The team needs to
recommend a solution that will prevent unapproved
devices from accessing the network.
Which solution fulfills these requirements?
A) Implementing a demilitarized zone (DMZ)
B) Installing a hardware security module
C) Implementing port security
D) Deploying a software firewall
The chief technology officer for a small publishing C) Deploying a unified threat management (UTM) appliance
company has been tasked with improving the
company's security posture. As part of a network
upgrade, the company has decided to implement
intrusion detection, spam filtering, content filtering, and
antivirus controls. The project needs to be completed
using the least amount of infrastructure while meeting
all requirements.
Which solution fulfills these requirements?
A) Deploying an anti-spam gateway
B) Deploying a proxy server
C) Deploying a unified threat management (UTM)
appliance
D) Deploying a web application firewall (WAF)
The security team plans to deploy an intrusion C) Signature-based detection
detection system (IDS) solution to alert engineers
about inbound threats. The team already has a database
of signatures that they want the IDS solution to validate.
Which detection technique meets the requirements?
A) Intrusion detection
B) Deep packet inspection
C) Signature-based detection
D) Intrusion prevention
, D488 - Cybersecurity Architecture and Engineering (CASP+) Exam
An IT organization had a security breach after C) Implementing versioning
deploying an update to its production web servers. The
application currently goes through a manual update
process a few times per year. The security team needs
to recommend a failback option for future
deployments.
Which solution fulfills these requirements?
A) Implementing a code scanner
B) Implementing code signing
C) Implementing versioning
D) Implementing a security requirements traceability
matrix (SRTM)
A software development team is working on a new C) Code signing
mobile application that will be used by customers. The
security team must ensure that builds of the application
will be trusted by a variety of mobile devices.
Which solution fulfills these requirements?
A) Code scanning
B) Regression testing
C) Code signing
D) Continuous delivery
An IT organization recently suffered a data leak C) Digital rights management (DRM)
incident. Management has asked the security team to
implement a print blocking mechanism for all
documents stored on a corporate file share.
Which solution fulfills these requirements?
A) Virtual desktop infrastructure (VDI)
B) Remote Desktop Protocol (RDP)
C) Digital rights management (DRM)
D) Watermarking
A company has recently discovered that a competitor is C) Digital rights management (DRM)
distributing copyrighted videos produced by the in-
house marketing team. Management has asked the
security team to prevent these types of violations in the
future.
Which solution fulfills these requirements?
A) Virtual desktop infrastructure (VDI)
B) Secure Socket Shell (SSH)
C) Digital rights management (DRM)
D) Remote Desktop Protocol (RDP)
, D488 - Cybersecurity Architecture and Engineering (CASP+) Exam
A security team has been tasked with performing C) Automatically
regular vulnerability scans for a cloud-based
infrastructure.
How should these vulnerability scans be conducted
when implementing zero trust security?
A) Manually
B) Annually
C) Automatically
D) As needed
A healthcare company needs to ensure that medical C) Anonymization
researchers cannot inadvertently share protected
health information (PHI) data from medical records.
What is the best solution?
A) Encryption
B) Metadata
C) Anonymization
D) Obfuscation
A security team has been tasked with mitigating the risk C) Privileged access management (PAM)
of stolen credentials after a recent breach. The solution
must isolate the use of privileged accounts. In the
future, administrators must request access to mission-
critical services before they can perform their tasks.
What is the best solution?
A) Identity and access management (IAM)
B) Password policies
C) Privileged access management (PAM)
D) Password complexity
A global manufacturing company is moving its C) Attribute-based access control (ABAC)
applications to the cloud. The security team has been
tasked with hardening the access controls for a
corporate web application that was recently migrated.
End users should be granted access to different
features based on their locations and departments.
Which access control solution should be implemented?
A) Kerberos
B) Mandatory access control (MAC)
C) Attribute-based access control (ABAC)
D) Privileged access management (PAM)
, D488 - Cybersecurity Architecture and Engineering (CASP+) Exam
A team of developers is building a new corporate web C) Out-of-band authentication
application. The security team has stated that the
application must authenticate users through two
separate channels of communication.
Which type of authentication method should the
developers include when building the application?
A) In-band authentication
B) Kerberos
C) Out-of-band authentication
D) Challenge-Handshake Authentication Protocol
(CHAP)
An IT organization is implementing a hybrid cloud C) Single sign-on (SSO)
deployment. Users should be able to sign in to all
corporate resources using their email addresses as their
usernames, regardless of whether they are accessing an
application on-premises or in the cloud.
Which solution meets this requirement?
A) JSON Web Token (JWT)
B) Trusted Platform Module (TPM)
C) Single sign-on (SSO)
D) Internet Protocol Security (IPsec)
The security team has been tasked with implementing a C) Open Authentication (OAuth)
secure authorization protocol for its web applications.
Which of the following protocols provides the best
method for securely authenticating users and granting
access?
A) Simple network management protocol (SNMP)
B) Extensible Authentication Protocol (EAP)
C) Open Authentication (OAuth)
D) Secure Sockets Layer (SSL)
An IT team is preparing the network for a hybrid cloud C) Advanced persistent threat
deployment. A security analyst recently discovered that
the firmware of a router in the core data center has
been compromised. According to the analyst, the
attack occurred over a year ago without being
detected.
Which type of threat actor is the most likely cause of
the attack?
A) Competitor
B) Hacktivist
C) Advanced persistent threat
D) Novice hacker