| Exam Code/Number: | CAS-005Join the discussion |
| Exam Name: | CompTIA SecurityX Certification Exam |
| Certification: | CompTIA |
| Question Number: | 604 |
| Publish Date: | Aug 29, 2026 |
|
Rating
100%
|
|
An organization's vulnerability management team is reviewing the following output from a scan of a production server:
Finding ID | Summary
Weak cryptographic library | The device allows the use of weak
cryptographic libraries.
End-of-life, third-party library | The running service includes an end- of-life, third-party library.
Remote service detected | The device is running FTP on TCP port 21.
End-of-life operating system | The operating system has reached end-of- life status.
Database detected | This device includes an installed database.
Which of the following should the team do first?
A company recently acquired a manufacturing plant. The acquiring company plans to create a unified network that does not impact its security posture. The manufacturing plant has been in operation for more than 30 years and has not followed an equipment replacement life cycle.
Which of the following is the best way to meet this objective?
SIMULATION
A product development team has submitted code snippets for review prior to release.
INSTRUCTIONS
Analyze the code snippets, and then select one vulnerability, and one fix for each code snippet.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Code Snippet 1
Code Snippet 2


A company was recently infected by malware. During the root cause analysis, the company determined that several users were installing their own applications. To prevent further compromises, the company has decided it will only allow authorized applications to run on its systems. Which of the following should the company implement?
A security administrator has isolated a computer system because it was targeted by a ransomware attack. Which of the following should the security administrator do to recover from this attack in the most secure way?