
CompTIASecurityX (CASP+)
Domain 4Objective 2
Vulnerabilities and Attack Surface CAS-005 Practice Questions (Page 7)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
9concepts
22%of the exam
Questions 31–33
- 31
A security team is hardening a web server's SSL/TLS configuration. Which cipher should be disabled to avoid using a weak cryptographic algorithm?
Select an answer first - 32
A network administrator notices that a firewall has an overly permissive rule allowing all inbound traffic from the internet to an internal database server. What is the most appropriate action to rectify this insecure configuration?
Select an answer first - 33
A web application reflects user input in an error message without proper encoding. An attacker crafts a URL that causes the application to display an alert box. Which type of XSS is this, and what is the most effective mitigation?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CAS-005
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.