CAS002 CompTIA Advanced Security Practitioner (CASP) Free Practice Test — 30 Questions

Exam Code: CASP

30 questions · Full explanations · No account required

Free
Question 1 of 30

A global financial services firm\'s security operations center (SOC) is alerted to a sophisticated, multi-stage ransomware attack that has encrypted critical customer databases. The attack appears to have originated from a zero-day exploit targeting a web application. The incident response team is under extreme pressure to restore services within hours to avoid significant financial losses and regulatory penalties under frameworks like PCI DSS and SOX. Which course of action best balances the immediate need for service restoration with the imperative to preserve evidence for forensic analysis and potential legal action?

Immediately disconnect all affected servers from the network and initiate restoration from the most recent, verified clean backup to minimize downtime.
Proceed with a full system wipe and re-imaging of all compromised servers to ensure a clean state, then restore essential services from available data repositories.
Conduct forensic imaging of all compromised systems to preserve volatile and non-volatile data, segment the network to contain the spread, and then initiate recovery from verified backups.
Prioritize immediate communication with regulatory bodies and key stakeholders about the breach, outlining the known impact, while simultaneously attempting to isolate critical network segments.

About the CAS002 CompTIA Advanced Security Practitioner (CASP) Certification

These free practice questions are designed to help you assess your readiness for the CAS002 CompTIA Advanced Security Practitioner (CASP) exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.