CAS-004 Dumps (2024) Prepare Your Exam With 362 Questions [Q63-Q84]

Share

CAS-004 Dumps (2024) Prepare Your Exam With 362 Questions

New CAS-004 Dumps - Real CompTIA Exam Questions


CompTIA CAS-004, also known as the CompTIA Advanced Security Practitioner (CASP+) certification exam, is one of the most prestigious and globally recognized certifications in the field of information security. CAS-004 exam is designed for advanced-level IT security professionals who have at least ten years of experience in IT administration, with five years of hands-on technical security experience.


CompTIA CAS-004, also known as the CompTIA Advanced Security Practitioner (CASP+) exam, is a certification exam designed for experienced IT professionals who are looking to advance their careers in cybersecurity. CompTIA Advanced Security Practitioner (CASP+) Exam certification validates the knowledge and skills required to conceptualize, design, and implement complex security solutions across a variety of environments. CAS-004 exam covers a range of topics, including risk management, enterprise security architecture, research and collaboration, and integration of computing, communications, and business disciplines.

 

NEW QUESTION # 63
An auditor Is reviewing the logs from a web application to determine the source of an Incident.
The web application architecture Includes an Internet-accessible application load balancer, a number of web servers In a private subnet, application servers, and one database server In a tiered configuration. The application load balancer cannot store the logs. The following are sample log snippets:

Which of the following should the auditor recommend to ensure future incidents can be traced back to the sources?

  • A. Install a software-based HIDS on the application servers.
  • B. Store the value of the $_SERVER['REMOTE_ADDR'] received by the web servers.
  • C. Enable the x-Forwarded-For header al the load balancer.
  • D. Install a certificate signed by a trusted CA.
  • E. Use stored procedures on the database server.

Answer: C

Explanation:
The X-Forwarded-For (XFF) HTTP header field is a common method for identifying the originating IP address of a client connecting to a web server through an HTTP proxy or load balancer.


NEW QUESTION # 64
A software company wants to build a platform by integrating with another company's established product. Which of the following provisions would be MOST important to include when drafting an agreement between the two companies?

  • A. Data sovereignty
  • B. Source code escrow
  • C. Safe harbor considerations
  • D. Shared responsibility

Answer: D

Explanation:
When drafting an agreement between two companies, it is important to clearly define the responsibilities of each party. This is particularly relevant when a software company is looking to integrate with an established product. A shared responsibility agreement ensures that both parties understand their respective responsibilities and are able to work together efficiently and effectively. For example, the software company might be responsible for integrating the product and ensuring it meets user needs, while the established product provider might be responsible for providing ongoing support and maintenance. By outlining these responsibilities in the agreement, both parties can ensure that the platform is built and maintained successfully. Reference: CompTIA Advanced Security Practitioner (CASP+) Study Guide, Chapter 8, Working with Third Parties.


NEW QUESTION # 65
A company that uses AD is migrating services from LDAP to secure LDAP. During the pilot phase, services are not connecting properly to secure LDAP. Block is an except of output from the troubleshooting session:

Which of the following BEST explains why secure LDAP is not working? (Select TWO.)

  • A. Danvills.com is under a DDoS-inator attack and cannot respond to OCSP requests.
  • B. The clients may not trust Chicago by default.
  • C. The company is using the wrong port. It should be using port 389 for secure LDAP.
  • D. Secure LDAP should be running on UDP rather than TCP.
  • E. Secure LDAP does not support wildcard certificates.
  • F. The clients may not trust idapt by default.
  • G. The secure LDAP service is not started, so no connections can be made.

Answer: C,G


NEW QUESTION # 66
An organization is deploying a new, online digital bank and needs to ensure availability and performance. The cloud-based architecture is deployed using PaaS and SaaS solutions, and it was designed with the following considerations:
- Protection from DoS attacks against its infrastructure and web applications is in place.
- Highly available and distributed DNS is implemented.
- Static content is cached in the CDN.
- A WAF is deployed inline and is in block mode.
- Multiple public clouds are utilized in an active-passive architecture.
With the above controls in place, the bank is experiencing a slowdown on the unauthenticated payments page.
Which of the following is the MOST likely cause?

  • A. The site is experiencing a brute-force credential attack.
  • B. The public cloud provider is applying QoS to the inbound customer traffic.
  • C. The API gateway endpoints are being directly targeted.
  • D. A DDoS attack is targeted at the CDN.

Answer: B


NEW QUESTION # 67
A development team created a mobile application that contacts a company's back-end APIs housed in a PaaS environment. The APIs have been experiencing high processor utilization due to scraping activities. The security engineer needs to recommend a solution that will prevent and remedy the behavior.
Which of the following would BEST safeguard the APIs? (Choose two.)

  • A. OAuth 2.0
  • B. CSRF protection
  • C. Input validation
  • D. Bot protection
  • E. Rate limiting
  • F. Autoscaling endpoints

Answer: D,E

Explanation:
Although I might agree that OAuth 2.0 could be an answer as well, since it can help with rate limiting by accepting only authorized traffic, this is not as specific as it should be for the proposed scenario.
Bot protection is a security measure that helps prevent automated scraping activities by detecting and blocking malicious bots that attempt to access the APIs. This can help reduce the processor utilization on the APIs and prevent scraping activities from affecting the performance of the system.
Rate limiting is a security measure that limits the number of requests that can be made to an API within a given time period. By implementing rate limiting, the security engineer can help prevent scraping activities that may cause high processor utilization on the APIs.


NEW QUESTION # 68
A user from the sales department opened a suspicious file attachment. The sales department then contacted the SOC to investigate a number of unresponsive systems, and the team successfully identified the file and the origin of the attack.
Which of the following is the NEXT step of the incident response plan?

  • A. Remediation
  • B. Recovery
  • C. Response
  • D. Containment

Answer: D

Explanation:
https://www.sciencedirect.com/topics/computer-science/containment-strategy


NEW QUESTION # 69
A company is implementing SSL inspection. During the next six months, multiple web applications that will be separated out with subdomains will be deployed.
Which of the following will allow the inspection of the data without multiple certificate deployments?

  • A. Create a wildcard certificate.
  • B. Implement certificate pinning.
  • C. Use a third-party C
  • D. Include all available cipher suites.

Answer: A


NEW QUESTION # 70
The Chief information Officer (CIO) asks the system administrator to improve email security at the company based on the following requirements:
- Transaction being requested by unauthorized individuals.
- Complete discretion regarding client names, account numbers, and
investment information.
- Malicious attackers using email to malware and ransomeware.
- Exfiltration of sensitive company information.
The cloud-based email solution will provide anti-malware reputation-based scanning, signature- based scanning, and sandboxing.
Which of the following is the BEST option to resolve the boar's concerns for this email migration?

  • A. Application whitelisting
  • B. Data loss prevention
  • C. Endpoint detection response
  • D. SSL VPN

Answer: B


NEW QUESTION # 71
An organization is developing a disaster recovery plan that requires data to be backed up and available at a moment's notice.
Which of the following should the organization consider FIRST to address this requirement?

  • A. Implement a change management plan to ensure systems are using the appropriate versions.
  • B. Identify critical business processes and determine associated software and hardware requirements.
  • C. Hire additional on-call staff to be deployed if an event occurs.
  • D. Design an appropriate warm site for business continuity.

Answer: B


NEW QUESTION # 72
An organization is evaluating options related to moving organizational assets to a cloud-based environment using an IaaS provider. One engineer has suggested connecting a second cloud environment within the organization's existing facilities to capitalize on available datacenter space and resources. Other project team members are concerned about such a commitment of organizational assets, and ask the Chief Security Officer (CSO) for input. The CSO explains that the project team should work with the engineer to evaluate the risks associated with using the datacenter to implement:

  • A. an on-premises private cloud.
  • B. a hosted hybrid cloud.
  • C. a hybrid cloud.
  • D. a private cloud.

Answer: B


NEW QUESTION # 73
To save time, a company that is developing a new VPN solution has decided to use the OpenSSL library within Its proprietary software. Which of the following should the company consider to maximize risk reduction from vulnerabilities introduced by OpenSSL?

  • A. Ensure the third-party library implements the TLS and disable weak ciphers.
  • B. Include stable, long-term releases of third-party libraries instead of using newer versions.
  • C. Implement an ongoing, third-party software and library review and regression testing.
  • D. Compile third-party libraries into the main code statically instead of using dynamic loading.

Answer: C

Explanation:
Explanation
Implementing an ongoing, third-party software and library review and regression testing is the best way to maximize risk reduction from vulnerabilities introduced by OpenSSL. Third-party software and libraries are often used by developers to save time and resources, but they may also introduce security risks if they are not properly maintained and updated. By reviewing and testing the third-party software and library regularly, the company can ensure that they are using the latest and most secure version of OpenSSL, and that their proprietary software is compatible and functional with it.
References: [CompTIA CASP+ Study Guide, Second Edition, page 362]


NEW QUESTION # 74
A software development company is building a new mobile application for its social media platform. The company wants to gain its Users' rust by reducing the risk of on-path attacks between the mobile client and its servers and by implementing stronger digital trust. To support users' trust, the company has released the following internal guidelines:
* Mobile clients should verify the identity of all social media servers locally.
* Social media servers should improve TLS performance of their certificate status.
* Social media servers should inform the client to only use HTTPS.
Given the above requirements, which of the following should the company implement? (Select TWO).

  • A. Distributed object model
  • B. Quick UDP internet connection
  • C. OCSP stapling
  • D. DNSSEC
  • E. Private CA
  • F. CRL
  • G. HSTS

Answer: C,G

Explanation:
Explanation
OCSP stapling and HSTS are the best options to meet the requirements of reducing the risk of on-path attacks and implementing stronger digital trust. OCSP stapling allows the social media servers to improve TLS performance by sending a signed certificate status along with the certificate, eliminating the need for the client to contact the CA separately. HSTS allows the social media servers to inform the client to only use HTTPS and prevent downgrade attacks.


NEW QUESTION # 75
A security consultant is designing an infrastructure security solution for a client company that has provided the following requirements:
* Access to critical web services at the edge must be redundant and highly available.
* Secure access services must be resilient to a proprietary zero-day vulnerability in a single component.
* Automated transition of secure access solutions must be able to be triggered by defined events or manually by security operations staff.
Which of the following solutions BEST meets these requirements?

  • A. Reverse TLS proxy configuration using OpenVPN/OpenSSL with scripted failover functionality that connects critical web services out to endpoint computers.
  • B. Implementation of multiple IPSec VPN solutions with diverse endpoint configurations enabling user optionality in the selection of a remote access provider
  • C. Two separate secure access solutions orchestrated by SOAR with components provided by the same vendor for compatibility.
  • D. Remote access services deployed using vendor-diverse redundancy with event response driven by playbooks.

Answer: D

Explanation:
Remote access services deployed using vendor-diverse redundancy with event response driven by playbooks is the best solution to meet the requirements. Vendor-diverse redundancy means using different vendors or technologies to provide the same service or function, which can increase the availability and resilience of the service. For example, if one vendor's VPN solution fails due to a zero-day vulnerability, another vendor's VPN solution can take over without affecting the users. Event response driven by playbooks means using predefined workflows or scripts to automate the actions or decisions that need to be taken in response to certain events or triggers. For example, a playbook can define how to switch between different remote access solutions based on certain criteria or conditions, such as performance, availability, security, or manual input. Playbooks can also be integrated with SOAR platforms to leverage their capabilities for orchestration, automation, and response. Verified Reference:
https://cyware.com/security-guides/security-orchestration-automation-and-response/what-is-vendor-agnostic-security-orchestration-automation-and-response-soar-40e4
https://www.paloaltonetworks.com/cyberpedia/what-is-a-security-playbook


NEW QUESTION # 76
During a recent security incident investigation, a security analyst mistakenly turned off the infected machine prior to consulting with a forensic analyst. upon rebooting the machine, a malicious script that was running as a background process was no longer present. As a result, potentially useful evidence was lost. Which of the following should the security analyst have followed?

  • A. Chain of custody
  • B. Secure storage
  • C. Verification
  • D. Order of volatility

Answer: D

Explanation:
Order of volatility is a procedure that a computer forensics examiner must follow during evidence collection. It refers to the order in which digital evidence is collected, starting with the most volatile and moving to the least volatile. Volatile data is data that is not permanent and is easily lost, such as data in memory when you turn off a computer. The security analyst should have followed the order of volatility to preserve the most fragile evidence first, such as the malicious script running as a background process, before turning off the infected machine. Verified Reference:
https://www.computer-forensics-recruiter.com/order-of-volatility/
https://www.sans.org/blog/best-practices-in-digital-evidence-collection/
https://blogs.getcertifiedgetahead.com/order-of-volatility/


NEW QUESTION # 77
An organization is developing a disaster recovery plan that requires data to be backed up and available at a moment's notice.
Which of the following should the organization consider FIRST to address this requirement?

  • A. Implement a change management plan to ensure systems are using the appropriate versions.
  • B. Identify critical business processes and determine associated software and hardware requirements.
  • C. Hire additional on-call staff to be deployed if an event occurs.
  • D. Design an appropriate warm site for business continuity.

Answer: B

Explanation:
When developing a plan, the first thing to consider is the business process and their impact on operations. A warm site does not make sense even if it were to be first, as a warm site does not replicate in a manner that provides "moments notice" fail over.


NEW QUESTION # 78
A company has decided to purchase a license for software that is used to operate a mission- critical process. The third-party developer is new to the industry but is delivering what the company needs at this time.
Which of the following BEST describes the reason why utilizing a source code escrow will reduce the operational risk to the company if the third party stops supporting the application?

  • A. The company will be able to manage the third-party developer's development process.
  • B. The company will be able to force the third-party developer to continue support.
  • C. The company will be paid by the third-party developer to hire a new development team.
  • D. The company will have access to the latest version to continue development.

Answer: D

Explanation:
Source Code Escrow - Identifies that a copy of vendor-developed source code is provided to a trusted third party in case the vendor ceases to be in business.


NEW QUESTION # 79
A cybersecurity analyst discovered a private key that could have been exposed.
Which of the following is the BEST way for the analyst to determine if the key has been compromised?

  • A. OCSP
  • B. CRL
  • C. CSRs
  • D. HSTS

Answer: C


NEW QUESTION # 80
A security analyst notices a number of SIEM events that show the following activity:

Which of the following response actions should the analyst take FIRST?

  • A. Disable local administrator privileges on the endpoints.
  • B. Disable powershell.exe on all Microsoft Windows endpoints.
  • C. Configure the forward proxy to block 40.90.23.154.
  • D. Restart Microsoft Windows Defender.

Answer: C

Explanation:
Explanation
top the data exfiltration and sever all malicious traffic first, and then clean up the internal mess.


NEW QUESTION # 81
Given the following log snippet from a web server:

Which of the following BEST describes this type of attack?

  • A. Cross-site scripting
  • B. Brute-force
  • C. SQL injection
  • D. Cross-site request forgery

Answer: C

Explanation:
Clearly trying to pass SQL code for the user field, this is clearly an example of SQL injection.
Cross site forgery is when you try to bypass or change the web path to by pass the index.


NEW QUESTION # 82
Due to adverse events, a medium-sized corporation suffered a major operational disruption that caused its servers to crash and experience a major power outage. Which of the following should be created to prevent this type of issue in the future?

  • A. BIA
  • B. SLA
  • C. BCM
  • D. RTO
  • E. BCP

Answer: E

Explanation:
BCP refers to the plan and processes used during a response to a disruptive event.


NEW QUESTION # 83
A software developer is working on a piece of code required by a new software package. The code should use a protocol to verify the validity of a remote identity. Which of the following should the developer implement in the code?

  • A. OCSP
  • B. RSA
  • C. CRL
  • D. HSTS

Answer: A

Explanation:
Another means of providing up to date information regarding the status of a certificate is to check the certificate's status on an Online Certificate Status Protocol (OCSP) server, referred to as an OCSP responder. Rather than return a whole CRL, this just communicates the status of the requested certificate. Details of the OCSP responder service should be published in the certificate.


NEW QUESTION # 84
......

Get Ready with CAS-004 Exam Dumps: https://www.actualtestsit.com/CompTIA/CAS-004-exam-prep-dumps.html

Dependable CAS-004 Exam Dumps to Become CompTIA Certified: https://drive.google.com/open?id=19fCQe8ECV1AvNVUqV9C12Wx2gwzPy7QU