CAS-005 Analyst Practice Questions
The free CAS-005: CompTIA SecurityX questions that deal with analyst, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #3
A security analyst discovered requests associated with IP addresses known for born legitimate 3nd bot-related traffic. Which of the following should the analyst use to determine whether the requests are malicious?
Correct answer: A
Explanation
The user-agent string can provide valuable information to distinguish between legitimate and bot-related traffic. It contains details about the browser, device, and sometimes the operating system of the client making the request. Why Use User-Agent String? • Identify Patterns: User-agent strings can help identify patterns that are typical of bots or legitimate users. • Block Malicious Bots: Many bots use known user-agent strings, and identifying these can help block malicious requests. • Anomalies Detection: Anomalous user-agent strings can indicate spoofing attempts or malicious activity. Other options provide useful information but may not be as effective for initial determination of the nature of the request: • B. Byte length of the request: This can indicate anomalies but does not provide detailed information about the client. • C. Web application headers: While useful, they may not provide enough distinction between legitimate and bot traffic. • D. HTML encoding field: This is not typically used for identifying the nature of the request. References: • CompTIA SecurityX Study Guide • "User-Agent Analysis for Security," OWASP • NIST Special Publication 800-94, "Guide to Intrusion Detection and Prevention Systems (IDPS)"
Question #10
An organization is looking for gaps in its detection capabilities based on the APTs that may target the industry Which of the following should the security analyst use to perform threat modeling?
Correct answer: A
Explanation
The ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is the best tool for a security analyst to use for threat modeling when looking for gaps in detection capabilities based on Advanced Persistent Threats (APTs) that may target the industry. Here's why: • Comprehensive Framework: ATT&CK provides a detailed and structured repository of known adversary tactics and techniques based on real-world observations. It helps organizations understand how attackers operate and what techniques they might use. • Gap Analysis: By mapping existing security controls against the ATT&CK matrix, analysts can identify which tactics and techniques are not adequately covered by current detection and mitigation measures. • Industry Relevance: The ATT&CK framework is continuously updated with the latest threat intelligence, making it highly relevant for industries facing APT threats. It provides insights into specific APT groups and their preferred methods of attack. • References:
Continue with CAS-005: CompTIA SecurityX Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in CAS-005: CompTIA SecurityX Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
