최신CompTIA SecurityX Certification - CAS-005무료샘플문제
A company migrated a critical workload from its data center to the cloud. The workload uses a very large data set that requires computational-intensive data processing. The business unit that uses the workload is projecting the following growth pattern:
- Storage requirements will double every six months.
- Computational requirements will fluctuate throughout the year.
- Average computational requirements will double every year.
Which of the following should the company do to address the business unit's requirements?
A government agency implements a configuration that disables cellular network access on government-issued devices while roaming internationally. The agency issues mobile hotspots and requires employees to use them for internet access. Which of the following best describes the agency's rationale?
After a leak of important documents, a company decides to implement a data protection program to avoid similar incidents in the future. Which of the following should the company do first?
A security architect needs to enable a container orchestrator for DevSecOps and SOAR initiatives. The engineer has discovered that several Ansible YAML files used for the automation of configuration management have the following content:

Which of the following should the engineer do to correct the security issues presented within this content?
During an incident response activity, the response team collected some artifacts from a compromised server, but the following information is missing:
- Source of the malicious files
- Initial attack vector
- Lateral movement activities
The next step in the playbook is to reconstruct a timeline. Which of the following best supports this effort?
During a security assessment, a penetration tester executed the following attack:

The tester then shared the results with the security analyst. Which of the following should the analyst do to remediate the attack?
A few security incidents involving user authentication issues occurred recently. The security team needs to implement technical controls that ensure:
- User accounts are difficult to compromise.
-Certain credentials are only used for specific applications.
-Users are only able to perform functions specified for their specific
roles.
-Passwords are not the only requirement for user authentication.
The security team has enabled role-based access control and password complexity requirements throughout the organization. Which of the following additional actions does the security team need to take? (Choose two.)
A cyberanalyst has been tasked with recovering PDF files from a provided image file. Which of the following is the best file-carving tool for PDF recovery?
A water power generation plant fails a security inspection. The controllers are distributed across a river that is 0.5mi (0.8km) wide. The controllers are connected via HTTP to the shoreside master controller. The distributed controllers and the shoreside controller communicate over the internet using a cellular network. The company cannot encrypt control traffic because the systems will not tolerate the additional overhead. Which of the following strategies is the best way to reduce the risk of compromise?
As part of a new software development method, a program manager requires that unit tests be written for all code before being promoted to production. The program manager wants to ensure that requirements can be tested and approved. Any security concerns should also be addressed prior to code deployment. Which of the following is an additional benefit of this new requirement?
A social media company wants to change encryption ciphers after identifying weaknesses in the implementation of the existing ciphers. The company needs the new ciphers to meet the following requirements:
- Utilize less RAM than competing ciphers.
- Be more CPU-efficient than previous ciphers.
- Require customers to use TLS 1.3 while broadcasting video or audio.
Which of the following is the best choice for the social media company?
The Chief Information Security Officer (CISO) asks the security team whether their SOC is receiving IoCs from an industry ISAC Which of the following is the most likely reason the CISO is interested in obtaining this information?