CompTIA CAS-001 시험 개요:
| 인증 벤더: | CompTIA |
|---|---|
| 시험명: | CompTIA Advanced Security Practitioner (CASP) CAS-001 |
| 시험 번호: | CAS-001 |
| 자격증 유효 기간: | 3년 |
| 합격 점수: | 750점 (100~900점 범위) |
| 실제 시험 문항 수: | 약 80문항 (객관식 및 실무 기반 문제) |
| 관련 자격증: | CompTIA Security+ CompTIA PenTest+ CompTIA CySA+ |
| 시험 형식: | 실무 기반 문제(PBQ), 객관식 문항 |
| 시험 시간: | 165분 |
| 지원 언어: | English |
| 응시료: | 349달러 (기존 가격이며, 지역 및 시기에 따라 변동될 수 있음) |
| 권장 교육: | CompTIA 학습 자료 CompTIA 공식 CASP 교육 과정 |
| 시험 등록: | Pearson VUE CompTIA 시험 안내 CompTIA 자격증 시험 등록 |
| 샘플 문제: | CompTIA CAS-001 샘플 문제 |
| 응시 방법: | Pearson VUE 시험 센터 및 온라인 감독 시험으로 응시 가능 (지역 및 시험 버전 현황에 따라 이용 가능 여부가 달라질 수 있음) |
| 전제 조건: | 정식 필수 요건은 없습니다. 권장 사항: 10년 이상의 일반 IT 경력 및 5년 이상의 실제 기술 보안 업무 경험 |
| 공식 요강 URL: | https://www.comptia.org/certifications |
CompTIA CAS-001 시험 요강 주제:
| 섹션 | 목표 |
|---|---|
| 주제 1: 연구, 개발 및 협업 | - 신기술 및 보안 영향 요인 - 보안 연구 및 위협 정보 분석 |
| 주제 2: 컴퓨팅, 통신 및 비즈니스 분야의 통합 | - 교차 도메인 보안 아키텍처 수립 - 보안 거버넌스 및 규제 준수 연계 - 안전한 엔터프라이즈 통합 전략 |
| 주제 3: 엔터프라이즈 보안 | - 엔터프라이즈 보안 통제 구현 - 보안 아키텍처 및 설계 원칙 - 신원 및 접근 관리 전략 |
| 주제 4: 리스크 관리 및 사고 대응 | - 업무 연속성 및 재해 복구 계획 - 사고 대응 절차 및 라이프사이클 - 리스크 평가 및 완화 전략 |
최신 CompTIA Advanced Security Practitioner CAS-001 무료샘플문제
문제 #1
A security manager has received the following email from the Chief Financial Officer (CFO):
"While I am concerned about the security of the proprietary financial data in our ERP application, we have had a lot of turnover in the accounting group and I am having a difficult time meeting our monthly performance targets. As things currently stand, we do not allow employees to work from home but this is something I am willing to allow so we can get back on track. What should we do first to securely enable this capability for my group?"
Based on the information provided, which of the following would be the MOST appropriate response to the CFO?
A. Remote access to the ERP tool introduces additional security vulnerabilities and should not be allowed.
B. Work with the executive management team to revise policies before allowing any remote access.
C. Allow terminal services access from personal computers after the CFO provides a list of the users working from home.
D. Allow VNC access to corporate desktops from personal computers for the users working from home.
문제 #2
The internal audit department is investigating a possible breach of security. One of the auditors is sent to interview the following employees:
Employee A. Works in the accounts receivable office and is in charge of entering data into the finance system.
Employee B. Works in the accounts payable office and is in charge of approving purchase orders.
Employee C. Is the manager of the finance department, supervises Employee A and Employee B, and can perform the functions of both Employee A and Employee B.
Which of the following should the auditor suggest be done to avoid future security breaches?
A. The manager should be able to both enter and approve information.
B. Employee A and Employee B should rotate jobs at a set interval and cross-train.
C. The manager should only be able to review the data and approve purchase orders.
D. All employees should have the same access level to be able to check on each others.
문제 #3
A financial institution wants to reduce the costs associated with managing and troubleshooting employees' desktops and applications, while keeping employees from copying data onto external storage. The Chief Information Officer (CIO) has asked the security team to evaluate four solutions submitted by the change management group. Which of the following BEST accomplishes this task?
A. Implement VDI and disable hardware and storage mapping from the thin client.
B. Implement desktop virtualization and encrypt all sensitive data at rest and in transit.
C. Move the critical applications to a private cloud and disable VPN and tunneling.
D. Implement server virtualization and move the application from the desktop to the server.
문제 #4
After a security incident, an administrator would like to implement policies that would help reduce fraud and the potential for collusion between employees. Which of the following would help meet these goals by having co-workers occasionally audit another worker's position?
A. Mandatory vacation
B. Separation of duties
C. Least privilege
D. Job rotation
문제 #5
The Universal Research Association has just been acquired by the Association of Medical Business Researchers. The new conglomerate has funds to upgrade or replace hardware as part of the acquisition, but cannot fund labor for major software projects. Which of the following will MOST likely result in some IT resources not being integrated?
A. One of the companies may use an outdated VDI.
B. Corporate websites may be optimized for different web browsers.
C. Industry security standards and regulations may be in conflict.
D. Data loss prevention standards in one company may be less stringent.
질문과 대답:
| 문제 #1 정답: B | 문제 #2 정답: C | 문제 #3 정답: A | 문제 #4 정답: D | 문제 #5 정답: C |














1439 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
