CompTIA CAS-004 Cert Guide PDF 100% Cover Real Exam Questions
Pass CAS-004 Exam - Real Questions and Answers
Passing the CompTIA CASP+ certification exam requires a deep understanding of complex security concepts and advanced technical skills. IT security professionals who pass the exam will have demonstrated their ability to think critically, implement security solutions, and manage risk. CompTIA Advanced Security Practitioner (CASP+) Exam certification will validate their skills in securing enterprise-level systems and networks, and they will be recognized as experts in the IT security industry.
NEW QUESTION # 140
Which of the following terms refers to the delivery of encryption keys to a CASB or a third-party entity?
- A. Key recovery
- B. Key escrow
- C. Key sharing
- D. Key distribution
Answer: D
Explanation:
Key Escrow is the process to store the key. Totally use key Escrow with CASB and third party but the deliver system is Key Distribution. In short escrow is method of storing and distribution is method of delivery.
https://csrc.nist.gov/glossary/term/key_distribution
https://jumpcloud.com/blog/key-escrow
NEW QUESTION # 141
A security administrator configured the account policies per security implementation guidelines. However, the accounts still appear to be susceptible to brute-force attacks. The following settings meet the existing compliance guidelines:
Must have a minimum of 15 characters
Must use one number
Must use one capital letter
Must not be one of the last 12 passwords used
Which of the following policies should be added to provide additional security?
- A. Password history
- B. Password complexity
- C. Shared accounts
- D. Account lockout
- E. Time-based logins
Answer: D
NEW QUESTION # 142
A security analyst notices a number of SIEM events that show the following activity:
Which of the following response actions should the analyst take FIRST?
- A. Configure the forward proxy to block 40.90.23.154.
- B. Disable powershell.exe on all Microsoft Windows endpoints.
- C. Restart Microsoft Windows Defender.
- D. Disable local administrator privileges on the endpoints.
Answer: A
NEW QUESTION # 143
During a remodel, a company's computer equipment was moved to a secure storage room with cameras positioned on both sides of the door. The door is locked using a card reader issued by the security team, and only the security team and department managers have access to the room. The company wants to be able to identify any unauthorized individuals who enter the storage room by following an authorized employee.
Which of the following processes would BEST satisfy this requirement?
- A. Monitor camera footage corresponding to a valid access request.
- B. Require both security and management to open the door.
- C. Require department managers to review denied-access requests.
- D. Issue new entry badges on a weekly basis.
Answer: B
NEW QUESTION # 144
A security administrator is performing an audit of a local network used by company guests and executes a series of commands that generates the following output:
Which of the following actions should the security administrator take to BEST mitigate the issue that transpires from the above information?
- A. Enforce static ARP mappings using GPO
- B. Implement 802 1X
- C. Enable unicast RPF
- D. Implement switchport security
Answer: D
NEW QUESTION # 145
The OS on several servers crashed around the same time for an unknown reason. The servers were restored to working condition, and all file integrity was verified. Which of the following should the incident response team perform to understand the crash and prevent it in the future?
- A. Lessons learned
- B. Continuity of operations plan
- C. Root cause analysis
- D. After-action report
Answer: C
NEW QUESTION # 146
A security engineer is reviewing a record of events after a recent data breach incident that Involved the following:
- A hacker conducted reconnaissance and developed a footprint of the
company s Internet-facing web application assets.
- A vulnerability in a third-party horary was exploited by the hacker,
resulting in the compromise of a local account.
- The hacker took advantage of the account's excessive privileges to
access a data store and exfilltrate the data without detection.
Which of the following is the BEST solution to help prevent this type of attack from being successful in the future?
- A. User behavior analysis
- B. Software composition analysis
- C. Dynamic analysis
- D. Web application firewall
- E. Secure web gateway
Answer: D
Explanation:
Why do you need a web application firewall (WAF)?
Maximizes the detection and catch rate for known and unknown threats
Minimizes false alerts (false positives) and adapts to continually evolving web applications Ensures broader adoption through ease of use and minimal performance impact
NEW QUESTION # 147
A company that all mobile devices be encrypted, commensurate with the full disk encryption scheme of assets, such as workstation, servers, and laptops. Which of the following will MOST likely be a limiting factor when selecting mobile device managers for the company?
- A. Inability to selected AES-256 encryption
- B. Unavailable of key escrow
- C. Increased network latency
- D. Removal of user authentication requirements
Answer: C
NEW QUESTION # 148
Device event logs sources from MDM software as follows:
Which of the following security concerns and response actions would BEST address the risks posed by the device in the logs?
- A. Resource leak; recover the device for analysis and clean up the local storage.
- B. Malicious installation of an application; change the MDM configuration to remove application ID
1220. - C. Falsified status reporting; remotely wipe the device.
- D. Impossible travel; disable the device's account and access while investigating.
Answer: D
Explanation:
Due to line 4, a GPS spoofing could be in use either by the newly install app, or before the app was installed.
NEW QUESTION # 149
An organization's finance system was recently attacked. A forensic analyst is reviewing the contents of the compromised files for credit card dat a. Which of the following commands should the analyst run to BEST determine whether financial data was lost?
- A. Option A
- B. Option D
- C. Option C
- D. Option B
Answer: C
NEW QUESTION # 150
A security architect for a large, multinational manufacturer needs to design and implement a security solution to monitor traffic.
When designing the solution, which of the following threats should the security architect focus on to prevent attacks against the OT network?
- A. Use of any non-DNP3 communication on a DNP3 port
- B. Packets that are the wrong size or length
- C. Application of an unsupported encryption algorithm
- D. Multiple solicited responses over time
Answer: A
Explanation:
The components of an ICS network are often described as an operational technology (OT) network, in contrast to an IT network, comprised of server and client computing devices.
Communications within an OT network are supported by a network application protocol such as Modbus. The communication protocol gives control servers and SCADA hosts the ability to query and change the configuration of each PLC. Modbus was originally designed as a serial protocol (Modbus RTU) running over a fieldbus network but has been adapted to use Ethernet and TCP/IP as well. Other protocols include EtherNet/IP, a variant of the Common Industrial Protocol (CIP), Distributed Network Protocol (DNP3), and Siemens S7comms.
NEW QUESTION # 151
A developer implement the following code snippet.
Which of the following vulnerabilities does the code snippet resolve?
- A. Information leakage
- B. SQL inject
- C. Buffer overflow
- D. Missing session limit
Answer: A
NEW QUESTION # 152
A cloud architect needs to isolate the most sensitive portion of the network while maintaining hosting in a public cloud.
Which of the following configurations can be employed to support this effort?
- A. Create a single-tenancy security group in the public cloud that hosts only similar types of servers
- B. Create a hybrid cloud with an on-premises instance for the most sensitive server types.
- C. Privatize the cloud by implementing an on-premises instance.
- D. Sandbox the servers with the public cloud by server type
Answer: B
NEW QUESTION # 153
A company is moving most of its customer-facing production systems to the cloud-facing production systems to the cloud. IaaS is the service model being used. The Chief Executive Officer is concerned about the type of encryption available and requires the solution must have the highest level of security.
Which of the following encryption methods should the cloud security engineer select during the implementation phase?
- A. Proxy-based
- B. Array controller-based
- C. Instance-based
- D. Storage-based
Answer: D
Explanation:
Explanation
We recommend that you encrypt your virtual hard disks (VHDs) to help protect your boot volume and data volumes at rest in storage, along with your encryption keys and secrets. Azure Disk Encryption helps you encrypt your Windows and Linux IaaS virtual machine disks. Azure Disk Encryption uses the industry-standard BitLocker feature of Windows and the DM-Crypt feature of Linux to provide volume encryption for the OS and the data disks. The solution is integrated with Azure Key Vault to help you control and manage the disk-encryption keys and secrets in your key vault subscription. The solution also ensures that all data on the virtual machine disks are encrypted at rest in Azure Storage.
https://docs.microsoft.com/en-us/azure/security/fundamentals/iaas
NEW QUESTION # 154
A security engineer was auditing an organization's current software development practice and discovered that multiple open-source libraries were Integrated into the organization's software.
The organization currently performs SAST and DAST on the software it develops.
Which of the following should the organization incorporate into the SDLC to ensure the security of the open-source libraries?
- A. Perform unit testing of the open-source libraries.
- B. Perform additional SAST/DAST on the open-source libraries.
- C. Implement the SDLC security guidelines.
- D. Track the library versions and monitor the CVE website for related vulnerabilities.
Answer: D
Explanation:
It is important to keep track of the versions of open-source libraries that are being used, and to monitor the CVE website for any vulnerabilities that have been identified in those libraries. This can help the organization stay aware of potential security issues and take appropriate action to address them.
Performing unit testing of the open-source libraries is not necessary, as unit testing is typically focused on testing individual units of code within the software, not on external libraries that are being used.
NEW QUESTION # 155
An enterprise's Chief Technology Officer (CTO) and Chief Information Security Officer (CISO) are meeting to discuss ongoing capacity and resource planning issues. The enterprise has experienced rapid, massive growth over the last 12 months, and the technology department is stretched thin for resources. A new accounting service is required to support the enterprise's growth, but the only available compute resources that meet the accounting service requirements are on the virtual platform, which is hosting the enterprise's website.
Which of the following should the CISO be MOST concerned about?
- A. A security vulnerability that is exploited on the website could expose the accounting service.
- B. Poor capacity planning could cause an oversubscribed host, leading to poor performance on the company's website.
- C. Transferring as many services as possible to a CSP could free up resources.
- D. The CTO does not have the budget available to purchase required resources and manage growth.
Answer: A
NEW QUESTION # 156
A large telecommunications equipment manufacturer needs to evaluate the strengths of security controls in a new telephone network supporting first responders. Which of the following techniques would the company use to evaluate data confidentiality controls?
- A. Code signing
- B. Eavesdropping
- C. RF sidelobe sniffing
- D. Cryptanalysis
- E. On-path
Answer: B
NEW QUESTION # 157
......
100% Free CAS-004 Daily Practice Exam With 472 Questions: https://pdftorrent.dumpexams.com/CAS-004-vce-torrent.html