Exam Code: CAS-002
Exam Name: CompTIA Advanced Security Practitioner Exam
Q&As: 532

An attacker attempts to create a DoS event against the VoIP system of a company. The attacker uses a tool to flood the network with a large number of SIP INVITE traffic. Which of the following would be LEAST likely to thwart such an attack?
A. Install IDS/IPS systems on the network
B. Force all SIP communication to be encrypted
C. Create separate VLANs for voice and data traffic
D. Implement QoS parameters on the switches
CAS-002 exam Correct Answer: D
Joe, the Chief Executive Officer (CEO), was an Information security professor and a Subject Matter Expert for over 20 years. He has designed a network defense method which he says is significantly better than prominent international standards. He has recommended that the company use his cryptographic method. Which of the following methodologies should be adopted?
A. The company should develop an in-house solution and keep the algorithm a secret.
B. The company should use the CEO’s encryption scheme.
C. The company should use a mixture of both systems to meet minimum standards.
D. The company should use the method recommended by other respected information security organizations.
Correct Answer: D
A small company’s Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company’s security posture quickly with regard to targeted attacks. Which of the following should the CSO conduct FIRST?
A. Survey threat feeds from services inside the same industry.
B. Purchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.
C. Conduct an internal audit against industry best practices to perform a qualitative analysis.
D. Deploy a UTM solution that receives frequent updates from a trusted industry vendor.
CAS-002 dump Correct Answer: A
An administrator wants to enable policy based flexible mandatory access controls on an open source OS to prevent abnormal application modifications or executions. Which of the following would BEST accomplish this?
A. Access control lists
B. SELinux
C. IPtables firewall
Correct Answer: B
Company XYZ has purchased and is now deploying a new HTML5 application. The company wants to hire a penetration tester to evaluate the security of the client and server components of the proprietary web application before launch. Which of the following is the penetration tester MOST likely to use while performing black box testing of the security of the company’s purchased application? (Select TWO).
A. Code review
B. Sandbox
C. Local proxy
D. Fuzzer
E. Port scanner
CAS-002 pdf Correct Answer: CD
What value should the AFI be set to for locally administered addressing?
A. 1
B. 49

C. 83
D. 0
Correct Answer: B
What are the similarities between OSPF and IS-IS? Choose two.
A. Metric is cost based
B. Slow convergence
C. Automatic summarization
D. Support CIDR
CAS-002 vce Correct Answer: AD
The following IS-IS packets have been exchanged between 2 adjacent IS-IS routers. What type of
adjacency will be formed?
A. An L1 adjacency will be formed.
B. An L1/L2 adjacency will formed
C. L2 adjacency will be formed
D. No adjacency will be formed
Correct Answer: D
Which of the following best describes how IS-IS routers exchange updates on an Ethernet interface?
A. IS-IS routers exchange updates by sending UDP packets to a multicast address.

B. IS-IS routers exchange updates using IP multicast packets.
C. IS-IS routers exchange updates using Ethernet multicast packets.
D. IS-IS routers exchange updates by sending packets to the subnet broadcast address.
CAS-002 exam Correct Answer: C
What acts as the tie breaker on an Alcatel-Lucent 7750 SR if the priorities are the same when IS- IS is electing a DIS?
A. The system ID
B. The loopback address
C. The sequence number of the hello packet
D. The device that first initiated communication becomes the DIS
Correct Answer: A
How many bytes make up the system ID in an IS-IS NSAP address on the Alcatel-Lucent 7750 SR?
A. 4 bytes
B. 6 bytes
C. 8 bytes
D. Variably between 4 and 8 bytes
CAS-002 dump Correct Answer: B
In an OSPF Hello packet what fields must match all neighbor routers on the segment? (Choose 3)
A. Area ID
B. Hello and Dead Intervals
C. Stub flag
D. DR and BDR addresses
E. The list of neighbors
Correct Answer: ABC
What type of OSPF router generates a type 2 LSA?
A. Area Border Router
B. Autonomous System Boundary Router
C. Designated Router
D. All routers within an OSPF area.
CAS-002 pdf Correct Answer: C
What is the default priority value used for electing the DR on an Alcatel-Lucent 7750 SR running OSPF on
an Ethernet?
A. Priority of 0
B. Priority of 1
C. Priority of 64
D. Priority of 255

Correct Answer: B
Which of the following statements regarding the election of the designated router (DR) by OSPF routers are true? (Choose two)
A. The router with the lowest priority is the DR.
B. The router with the highest priority is the DR.
C. If priorities are the same, the DR is chosen based on the lowest RID.
D. If priorities are the same, the DR is chosen based on the highest RID.
CAS-002 vce Correct Answer: BD
What are the types of networks supported on an Alcatel-Lucent 7750 SR for OSPF? (Choose 2)
A. Broadcast
B. Non-Broadcast Multi-Access
C. Point-to-Point
D. Point-to-Multipoint
Correct Answer: AC
What are the ways the RID can be created on an Alcatel-Lucent 7750 SR router? (Choose three)
A. From the last 32 bits of the chassis MAC address
B. From the first 32 bits of the chassis MAC address
C. The loopback IP address
D. By using the command “config router ospf rid X.X.X.X”
E. From the system IP address
F. From the highest interface IP address
CAS-002 exam Correct Answer: ADE
Given the two configurations shown, identify the two incorrect statements below: (Choose two)
A. Both routers will generate OSPF Hello packets.
B. The system interface is missing in one configuration so OSPF will not operate correctly.
C. The interface type settings differ, but OSPF will still operate correctly.
D. Metric values differ, but this does not prevent OSPF operation.
Correct Answer: BC

