[Q168-Q185] The Best Valid CAS-004 Dumps for Helping Passing CAS-004 Exam!

Share

The Best Valid CAS-004 Dumps for Helping Passing CAS-004 Exam!

UPDATED CompTIA CAS-004 Exam Questions & Answer


To be eligible for the CASP+ certification exam, candidates must have a minimum of ten years of experience in IT administration, including a minimum of five years of hands-on technical security experience. CompTIA Advanced Security Practitioner (CASP+) Exam certification exam is intended to validate the candidate's knowledge and skills in advanced-level cybersecurity concepts and practices. CompTIA Advanced Security Practitioner (CASP+) Exam certification will demonstrate to employers that the candidate has the expertise and experience to design, implement, and manage cybersecurity solutions at the enterprise level.


CompTIA CAS-004 certification exam is designed to test the knowledge and skills of IT professionals in advanced security practices. CompTIA Advanced Security Practitioner (CASP+) Exam certification is intended for individuals who have a minimum of 5 years of experience in IT administration, including at least 10 years of experience in information security. CAS-004 exam is a validation of the expertise and proficiency of an individual in the field of cybersecurity, and passing it is a recognition of their advanced knowledge and skills.


CompTIA CAS-004 exam covers a wide range of topics related to cybersecurity, including risk management, enterprise security architecture, research and collaboration, and integration of computing, communications, and business disciplines. CAS-004 exam also tests the candidate's knowledge of advanced security concepts such as cryptography, identity and access management, and secure communication protocols.

 

NEW QUESTION # 168
An organization is planning for disaster recovery and continuity of operations.
INSTRUCTIONS
Review the following scenarios and instructions. Match each relevant finding to the affected host.
After associating scenario 3 with the appropriate host(s), click the host to select the appropriate corrective action for that finding.
Each finding may be used more than once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Answer:

Explanation:


NEW QUESTION # 169
A company just released a new video card. Due to limited supply and nigh demand, attackers are employing automated systems to purchase the device through the company's web store so they can resell it on the secondary market. The company's Intended customers are frustrated. A security engineer suggests implementing a CAPTCHA system on the web store to help reduce the number of video cards purchased through automated systems.
Which of the following now describes the level of risk?

  • A. Residual
  • B. Transferred
  • C. Mitigated
  • D. Low
  • E. Inherent

Answer: A

Explanation:
CAPTCHA does not completely mitigate the risk of Bots but rather reduces the risk and therefore Residual risk remains after the CAPTCHA implementation.


NEW QUESTION # 170
A threat analyst notices the following URL while going through the HTTP logs.

Which of the following attack types is the threat analyst seeing?

  • A. Session hijacking
  • B. CSRF
  • C. XSS
  • D. SQL injection

Answer: C


NEW QUESTION # 171
Ransomware encrypted the entire human resources fileshare for a large financial institution. Security operations personnel were unaware of the activity until it was too late to stop it. The restoration will take approximately four hours, and the last backup occurred 48 hours ago. The management team has indicated that the RPO for a disaster recovery event for this data classification is 24 hours.
Based on RPO requirements, which of the following recommendations should the management team make?

  • A. Increase the frequency of backups and create SIEM alerts for IOCs.
  • B. Leave the current backup schedule intact and make the human resources fileshare read-only.
  • C. Decrease the frequency of backups and pay the ransom to decrypt the data.
  • D. Leave the current backup schedule intact and pay the ransom to decrypt the data.

Answer: A


NEW QUESTION # 172
A networking team asked a security administrator to enable Flash on its web browser. The networking team explained that an important legacy embedded system gathers SNMP information from various devices. The system can only be managed through a web browser running Flash. The embedded system will be replaced within the year but is still critical at the moment.
Which of the following should the security administrator do to mitigate the risk?

  • A. Isolate the management interface to a private VLAN where a legacy browser in a VM can be used as needed to manage the system.
  • B. Suggest that the networking team contact the original embedded system's vendor to get an update to the system that does not require Flash.
  • C. Air gap the legacy system from the network and dedicate a laptop with an end-of-life OS on it to connect to the system via crossover cable for management.
  • D. Explain to the networking team the reason Flash is no longer available and insist the team move up the timetable for replacement.

Answer: A


NEW QUESTION # 173
Which of the following is the MOST important cloud-specific risk from the CSP's viewpoint?

  • A. Resource exhaustion
  • B. Isolation control failure
  • C. Management plane breach
  • D. Insecure data deletion

Answer: D


NEW QUESTION # 174
A security architect is tasked with securing a new cloud-based videoconferencing and collaboration platform to support a new distributed workforce. The security architect's key objectives are to:
* Maintain customer trust
* Minimize data leakage
* Ensure non-repudiation
Which of the following would be the BEST set of recommendations from the security architect?

  • A. Enable watermarking, enable the user authentication requirement, and disable video recording.
  • B. Enable the user authentication requirement, enable end-to-end encryption, and enable waiting rooms.
  • C. Disable file exchange, enable watermarking, and enable the user authentication requirement.
  • D. Enable end-to-end encryption, disable video recording, and disable file exchange.

Answer: C

Explanation:
Disabling file exchange can help to minimize data leakage by preventing users from sharing sensitive documents or data through the videoconferencing platform. Enabling watermarking can help to maintain customer trust and ensure non-repudiation by adding a visible or invisible mark to the video stream that identifies the source or owner of the content. Enabling the user authentication requirement can help to secure the videoconferencing sessions by verifying the identity of the participants and preventing unauthorized access. Verified References:
https://www.rev.com/blog/marketing/follow-these-7-video-conferencing-security-best-practices
https://www.paloaltonetworks.com/blog/2020/04/network-video-conferencing-security/
https://www.megameeting.com/news/best-practices-secure-video-conferencing/


NEW QUESTION # 175
A company is moving most of its customer-facing production systems to the cloud-facing production systems to the cloud. IaaS is the service model being used. The Chief Executive Officer is concerned about the type of encryption available and requires the solution must have the highest level of security.
Which of the following encryption methods should the cloud security engineer select during the implementation phase?

  • A. Proxy-based
  • B. Array controller-based
  • C. Storage-based
  • D. Instance-based

Answer: C

Explanation:
Explanation
We recommend that you encrypt your virtual hard disks (VHDs) to help protect your boot volume and data volumes at rest in storage, along with your encryption keys and secrets. Azure Disk Encryption helps you encrypt your Windows and Linux IaaS virtual machine disks. Azure Disk Encryption uses the industry-standard BitLocker feature of Windows and the DM-Crypt feature of Linux to provide volume encryption for the OS and the data disks. The solution is integrated with Azure Key Vault to help you control and manage the disk-encryption keys and secrets in your key vault subscription. The solution also ensures that all data on the virtual machine disks are encrypted at rest in Azure Storage.https://docs.microsoft.com/en-us/azure/security/fundamentals/iaas


NEW QUESTION # 176
A software development company is building a new mobile application for its social media platform. The company wants to gain its users' trust by reducing the risk of on-path attacks between the mobile client and its servers and by implementing stronger digital trust. To support users' trust, the company has released the following internal guidelines:
* Mobile clients should verify the identity of all social media servers locally.
* Social media servers should improve TLS performance of their certificate status
* Social media servers should inform the client to only use HTTPS.
Given the above requirements, which of the following should the company implement? (Select TWO).

  • A. DNSSEC
  • B. Private CA
  • C. HSTS
  • D. OCSP stapling
  • E. Distributed object model
  • F. CRL
  • G. Quick UDP internet connection

Answer: C,D

Explanation:
The company should implement OCSP stapling and HSTS to improve TLS performance and enforce HTTPS.
OCSP stapling is a technique that allows a server to provide a signed proof of the validity of its certificate along with the TLS handshake, instead of relying on the client to contact the certificate authority (CA) for verification. This can reduce the latency and bandwidth of the TLS handshake, as well as improve the privacy and security of the certificate status. HSTS stands for HTTP Strict Transport Security, which is a mechanism that instructs browsers to only use HTTPS when connecting to a website, and to reject any unencrypted or invalid connections. This can prevent downgrade attacks, man-in-the-middle attacks, and mixed content errors, as well as improve the performance of HTTPS connections by avoiding unnecessary redirects. Verified References:
https://www.techtarget.com/searchsecurity/definition/OCSP-stapling
https://www.techtarget.com/searchsecurity/definition/HTTP-Strict-Transport-Security
https://www.cloudflare.com/learning/ssl/what-is-hsts/


NEW QUESTION # 177
A vulnerability analyst identified a zero-day vulnerability in a company's internally developed software. Since the current vulnerability management system does not have any checks for this vulnerability, an engineer has been asked to create one.
Which of the following would be BEST suited to meet these requirements?

  • A. Node.js
  • B. OVAL
  • C. ISACs
  • D. ARF

Answer: B


NEW QUESTION # 178
An organization recently started processing, transmitting, and storing its customers' credit card information.
Within a week of doing so, the organization suffered a massive breach that resulted in the exposure of the customers' information.
Which of the following provides the BEST guidance for protecting such information while it is at rest and in transit?

  • A. ISO
  • B. PCI DSS
  • C. GDPR
  • D. NIST

Answer: B


NEW QUESTION # 179
An organization is assessing the security posture of a new SaaS CRM system that handles sensitive Pll and identity information, such as passport numbers. The SaaS CRM system does not meet the organization's current security standards. The assessment identifies the following:
1) There will be a $20,000 per day revenue loss for each day the system is delayed going into production.
2) The inherent risk is high.
3) The residual risk is low.
4) There will be a staged deployment to the solution rollout to the contact center.
Which of the following risk-handling techniques will BEST meet the organization's requirements?

  • A. Avoid the risk by accepting the shared responsibility model with the SaaS CRM provider.
  • B. Accept the risk, as compensating controls have been implemented to manage the risk.
  • C. Apply for a security exemption, as the risk is too high to accept.
  • D. Transfer the risk to the SaaS CRM vendor, as the organization is using a cloud service.

Answer: A


NEW QUESTION # 180
A company suspects a web server may have been infiltrated by a rival corporation. The security engineer reviews the web server logs and finds the following:

The security engineer looks at the code with a developer, and they determine the log entry is created when the following line is run:

Which of the following is an appropriate security control the company should implement?

  • A. Separate the items in the system call to prevent command injection.
  • B. Use server-side processing to avoid XSS vulnerabilities in path input.
  • C. Parameterize a query in the path variable to prevent SQL injection.
  • D. Restrict directory permission to read-only access.

Answer: A

Explanation:
Explanation
The company using the wrong port is the most likely root cause of why secure LDAP is not working. Secure LDAP is a protocol that provides secure communication between clients and servers using LDAP (Lightweight Directory Access Protocol), which is a protocol that allows querying and modifying directory services over TCP/IP. Secure LDAP uses SSL (Secure Sockets Layer) or TLS (Transport Layer Security) to encrypt LDAP traffic and prevent unauthorized disclosure or interception.


NEW QUESTION # 181
A company hired a third party to develop software as part of its strategy to be quicker to market. The company's policy outlines the following requirements:
https://i.postimg.cc/8P9sB3zx/image.png
The credentials used to publish production software to the container registry should be stored in a secure location.
Access should be restricted to the pipeline service account, without the ability for the third-party developer to read the credentials directly.
Which of the following would be the BEST recommendation for storing and monitoring access to these shared credentials?

  • A. MFA
  • B. TPM
  • C. Key vault
  • D. Local secure password file

Answer: C

Explanation:
Reference:
A key vault is a service that provides secure storage and management of keys, secrets, and certificates. It can be used to store credentials used to publish production software to the container registry in a secure location, and restrict access to the pipeline service account without allowing the third-party developer to read the credentials directly. A TPM (trusted platform module) is a hardware device that provides cryptographic functions and key storage, but it is not suitable for storing shared credentials. A local secure password file is a file that stores passwords in an encrypted format, but it is not as secure or scalable as a key vault. MFA (multi-factor authentication) is a method of verifying the identity of a user or device by requiring two or more factors, but it does not store credentials. Verified Reference: https://www.comptia.org/blog/what-is-a-key-vault https://partners.comptia.org/docs/default-source/resources/casp-content-guide


NEW QUESTION # 182
A new web server must comply with new secure-by-design principles and PCI DSS. This includes mitigating the risk of an on-path attack. A security analyst is reviewing the following web server configuration:

Which of the following ciphers should the security analyst remove to support the business requirements?

  • A. TLS_AES_128_CCM_8_SHA256
  • B. TLS_CHACHA20_POLY1305_SHA256
  • C. TLS_AES_128_GCM_SHA256
  • D. TLS_DHE_DSS_WITH_RC4_128_SHA

Answer: D

Explanation:
The security analyst should remove the cipher TLS_DHE_DSS_WITH_RC4_128_SHA to support the business requirements, as it is considered weak and vulnerable to on-path attacks. RC4 is an outdated stream cipher that has been deprecated by major browsers and protocols due to its flaws and weaknesses. The other ciphers are more secure and compliant with secure-by-design principles and PCI DSS. Verified References:
https://www.comptia.org/blog/what-is-a-cipher
https://partners.comptia.org/docs/default-source/resources/casp-content-guide


NEW QUESTION # 183
An organization is designing a MAC scheme (or critical servers running GNU/Linux. The security engineer is investigating SELinux but is confused about how to read labeling contexts. The engineer executes the command stat ./secretfile and receives the following output:

Which of the following describes the correct order of labels shown in the output above?

  • A. Role, type MLS level, and user identity
  • B. Object MLS level, role, and type
  • C. User identity, role, type, and MLS level
  • D. Object, user identity, role, and MLS level
  • E. Role, user identity, object, and MLS level

Answer: C

Explanation:
SELinux contexts are typically made up of several components, including the user identity, role, type (also known as domain or type), and MLS (Multi-Level Security) level. The context format is user:role:type:level. In the given output sys:secret:sec_t:s0, 'sys' represents the user identity, 'secret' is the role, 'sec_t' is the type, and 's0' is the MLS level. Understanding SELinux contexts is critical for managing Mandatory Access Control (MAC) in GNU/Linux systems to protect against unauthorized access.


NEW QUESTION # 184
A development team created a mobile application that contacts a company's back-end APIs housed in a PaaS environment. The APIs have been experiencing high processor utilization due to scraping activities. The security engineer needs to recommend a solution that will prevent and remedy the behavior.
Which of the following would BEST safeguard the APIs? (Choose two.)

  • A. Input validation
  • B. Bot protection
  • C. Autoscaling endpoints
  • D. CSRF protection
  • E. Rate limiting
  • F. OAuth 2.0

Answer: C,E


NEW QUESTION # 185
......

Updated CAS-004 Dumps Questions For CompTIA Exam: https://www.vceengine.com/CAS-004-vce-test-engine.html

Latest Success Metrics For Actual CAS-004 Exam Realistic Dumps: https://drive.google.com/open?id=1lqM5DcJiT1Lqj-HKP8XI7wz4m8Byf0HH