• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 47 pages
Exam (elaborations)

CASP 1 UPDATED ACTUAL Exam Questions and CORRECT Answers

Document preview thumbnail
Preview 4 out of 47 pages

CASP 1 UPDATED ACTUAL Exam Questions and CORRECT Answers Which of the following attacks does Unicast Reverse Path Forwarding prevent? A. Man in the Middle B. ARP poisoning C. Broadcast storm D. IP Spoofing - CORRECT ANSWER - D. IP Spoofing Which of the following authentication types is used primarily to authenticate users through

Content preview

CASP 1 UPDATED ACTUAL Exam
Questions and CORRECT Answers
Which of the following attacks does Unicast Reverse Path Forwarding prevent?


A. Man in the Middle
B. ARP poisoning
C. Broadcast storm

D. IP Spoofing - CORRECT ANSWER - D. IP Spoofing


Which of the following authentication types is used primarily to authenticate users through the
use
of tickets?


A. LDAP
B. RADIUS
C. TACACS+

D. Kerberos - CORRECT ANSWER - D. Kerberos


A security consultant is evaluating forms which will be used on a company website. Which of
the
following techniques or terms is MOST effective at preventing malicious individuals from
successfully exploiting programming flaws in the website?


A. Anti-spam software
B. Application sandboxing
C. Data loss prevention

D. Input validation - CORRECT ANSWER - D. Input validation

,A security audit has uncovered that some of the encryption keys used to secure the company
B2B
financial transactions with its partners may be too weak. The security administrator needs to
implement a process to ensure that financial transactions will not be compromised if a weak
encryption key is found. Which of the following should the security administrator implement?


A. Entropy should be enabled on all SSLv2 transactions.
B. AES256-CBC should be implemented for all encrypted data.
C. PFS should be implemented on all VPN tunnels.

D. PFS should be implemented on all SSH connections. - CORRECT ANSWER - C. PFS
should be implemented on all VPN tunnels.


A company provides on-demand virtual computing for a sensitive project. The company
implements a fully virtualized datacenter and terminal server access with two-factor
authentication
for access to sensitive data. The security administrator at the company has uncovered a breach in
data confidentiality. Sensitive data was found on a hidden directory within the hypervisor. Which
of
the following has MOST likely occurred?


A. A stolen two factor token and a memory mapping RAM exploit were used to move data from
one virtual guest to an unauthorized similar token.
B. An employee with administrative access to the virtual guests was able to dump the guest
memory onto their mapped disk.
C. A host server was left un-patched and an attacker was able to use a VMEscape attack to gain
unauthorized access.
D. A virtual guest was left un-patched and an attacker was able to use a privilege escalation
attack

to gain unauthorized acce - CORRECT ANSWER - C. A host server was left un-patched
and an attacker was able to use a VMEscape attack to gain

,unauthorized access.


Company XYZ provides residential television cable service across a large region. The company's
board of directors is in the process of approving a deal with the following three
companies:
A National landline telephone provider
A Regional wireless telephone provider
An international Internet service provider
The board of directors at Company XYZ wants to keep the companies and billing separated.
While the Chief Information Officer (CIO) at Company XYZ is concerned about the
confidentiality
of Company XYZ's customer data and wants to share only minimal information about its
customers for the purpose of accounting, billing, and customer authentication.
The proposed solution must use open standards and must make it simple and seamless for
Company XYZ's customers to receive all four services.
Which of the following solutions is BEST suited for this scenario?


A. All four companies must implement a TACACS+ web based single - CORRECT
ANSWER - D. Company XYZ needs to install the IdP, while the partner companies need
to install the SP
portion of a Federated identity solution.


The security administrator at a bank is receiving numerous reports that customers are unable to
login to the bank website. Upon further investigation, the security administrator discovers that
the
name associated with the bank website points to an unauthorized IP address.
Which of the following solutions will MOST likely mitigate this type of attack?
A. Security awareness and user training
B. Recursive DNS from the root servers
C. Configuring and deploying TSIG

, D. Firewalls and IDS technologies - CORRECT ANSWER - C. Configuring and
deploying TSIG


A security administrator has finished building a Linux server which will host multiple virtual
machines through hypervisor technology. Management of the Linux server, including monitoring
server performance, is achieved through a third party web enabled application installed on the
Linux server. The security administrator is concerned about vulnerabilities in the web application
that may allow an attacker to retrieve data from the virtual machines.
Which of the following will BEST protect the data on the virtual machines from an attack?
A. The security administrator must install the third party web enabled application in a chroot
environment.
B. The security administrator must install a software firewall on both the Linux server and the
virtual machines.
C. The security administrator must install anti-virus software on both the Linux server and the
virtual machines.

D. The security administrator must install the data - CORRECT ANSWER - A. The
security administrator must install the third party web enabled application in a chroot
environment.


A breach at a government agency resulted in the public release of top secret information. The
Chief Information Security Officer has tasked a group of security professionals to deploy a
system
which will protect against such breaches in the future.
Which of the following can the government agency deploy to meet future security needs?
A. A DAC which enforces no read-up, a DAC which enforces no write-down, and a MAC which
uses an access matrix.
B. A MAC which enforces no write-up, a MAC which enforces no read-down, and a DAC which
uses an ACL.
C. A MAC which enforces no read-up, a MAC which enforces no write-down, and a DAC which

Document information

Uploaded on
June 24, 2025
Number of pages
47
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$14.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STANFORDGRADESS
4.0
(240)
Sold
1653
Followers
108
Items
119940
Last sold
9 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions