Official Bank 0/345

CompTIA SecurityX Certification (CAS-005) - CompTIA Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
345 Total Questions
1
Question
An IPSec solution is being deployed. The configuration files for both the VPN SIMULATION concentrator and the AAA server are shown in the diagram.

Complete the configuration files to meet the following requirements:

• The EAP method must use mutual certificate-based authentication (With
issued client certificates).

• The IKEv2 Cipher suite must be configured to the MOST secure
authenticated mode of operation,

• The secret must contain at least one uppercase character, one lowercase
character, one numeric character, and one special character, and it must meet a minimumlength requirement of eight characters, INSTRUCTIONS Click on the AAA server and VPN concentrator to complete the configuration. Fill in the appropriate fields and make selections from the drop-down menus.

Exhibit

VPN Concentrator: 144/368

Exhibit

VPN concentrator Select proposal Y
Select proposal
peap blowfish256 re-eap ( mds aes256ccm128 proposals - aes128ctr cast128 camellia256ctr !.. tis ttis plugins ( psk eap-radius (I aes256gcm128 secret = server =

•••
Reset to Default Save Close

AAA Server:

Exhibit
Reveal Only
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A company that relies on an COL system must keep it operating until a new solution is available

Which of the following is the most secure way to meet this goal?
Options
A Placing the system in a screened subnet and blocking access from internal resources
B Restricting system access to perform necessary maintenance by the IT team
C Enforcing strong credentials and improving monitoring capabilities
D Isolating the system and enforcing firewall rules to allow access to only required endpoints
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A global company with a remote workforce implemented a new VPN solution. After deploying the VPN solution to several hundred users, the help desk starts receiving reports of slow access to both internally and externally available applications. A security analyst reviews the following: VPN client routing: 0.0.0.0/0 → eth1

Which of the following solutions should the analyst use to fix this issue?
Options
A Implement DNS over HTTPS.
B Move the servers to a screened subnet.
C Enable split tunneling.
D Configure an NAC solution.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
A security analyst discovered requests associated with IP addresses known for born legitimate 3nd bot-related traffic. Which ofthe following should the analyst use to determine whether the requests are malicious?
Options
A HTML encoding field
B Web application headers
C Byte length of the request
D User-agent string
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A local government that is investigating a data exfiltration claim was asked to review the fingerprint of the malicious user's actions. An investigator took a forensic image of the VM and downloaded the image to a secured USB drive to share with the government. Which of the following should be taken into consideration during the process of releasing the drive to the government?
Options
A Order of volatility
B Key exchange
C Chain of custody
D Legal issues
E Encryption in transit
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.