2024 Latest CAS-004 dumps - Instant Download PDF
Updated Verified CAS-004 Downloadable Printable Exam Dumps
The CASP+ certification is ideal for those who have experience in the cybersecurity field and want to take their careers to the next level. It covers a wide range of topics, including risk management, enterprise security architecture, research, and collaboration, among others. CompTIA Advanced Security Practitioner (CASP+) Exam certification will help professionals demonstrate their ability to assess and mitigate risks, design secure solutions, and implement best practices to protect their organization's information assets.
CompTIA Advanced Security Practitioner (CASP+) Certification Exam, also known as CAS-004, is an advanced-level certification program designed for IT professionals who specialize in cybersecurity. It is a vendor-neutral certification offered by CompTIA and is recognized globally as a standard for advanced-level cybersecurity skills. CompTIA Advanced Security Practitioner (CASP+) Exam certification exam validates the candidates' knowledge and skills in enterprise security architecture, risk management, security operations, and security technology integration.
NEW QUESTION # 200
An organization thinks that its network has active, malicious activity on it. Which of the following capabilities would BEST help to expose the adversary?
- A. Performing a penetration test
- B. Enumerating asset configurations
- C. Expanding SOC functions to include hunting
- D. Installing a honeypot and other decoys
Answer: D
NEW QUESTION # 201
A company security engineer arrives at work to face the following scenario:
1) Website defacement
2) Calls from the company president indicating the website needs to be fixed Immediately because It Is damaging the brand
3) A Job offer from the company's competitor
4) A security analyst's investigative report, based on logs from the past six months, describing how lateral movement across the network from various IP addresses originating from a foreign adversary country resulted in exfiltrated data Which of the following threat actors Is MOST likely involved?
- A. Organized crime
- B. APT/nation-state
- C. Competitor
- D. Script kiddie
Answer: B
Explanation:
Explanation
An Advanced Persistent Threat (APT) is an attack that is targeted, well-planned, and conducted over a long period of time by a nation-state actor. The evidence provided in the scenario indicates that the security analyst has identified a foreign adversary, which is strong evidence that an APT/nation-state actor is responsible for the attack. Resources:
CompTIA Advanced Security Practitioner (CASP+) Study Guide, Chapter 5: "Advanced Persistent Threats," Wiley,
2018. https://www.wiley.com/en-us/CompTIA+Advanced+Security+Practitioner+CASP%2B+Study+Guide%2C
NEW QUESTION # 202
A security analyst is investigating a possible buffer overflow attack. The following output was found on a user's workstation:
graphic.linux_randomization.prg
Which of the following technologies would mitigate the manipulation of memory segments?
- A. ASLR
- B. DEP
- C. HSM
- D. NX bit
Answer: A
Explanation:
https://eklitzke.org/memory-protection-and-aslr
NEW QUESTION # 203
Which of the following is a benefit of using steganalysis techniques in forensic response?
- A. Identifying least significant bit encoding of data in a .wav file
- B. Determining the frequency of unique attacks against DRM-protected media
- C. Breaking a symmetric cipher used in secure voice communications
- D. Maintaining chain of custody for acquired evidence
Answer: B
NEW QUESTION # 204
A security engineer is making certain URLs from an internal application available on the Internet.
The development team requires the following
- The URLs are accessible only from internal IP addresses
- Certain countries are restricted
- TLS is implemented.
- System users transparently access internal application services in a
round robin to maximize performance
Which of the following should the security engineer deploy?
- A. A load balancer with GeolP restrictions and least-load-sensing traffic distribution
- B. DNS to direct traffic and a WAF with only the specific external URLs configured
- C. A load balancer with IP ACL restrictions and a commercially available PKI certificate
- D. An application-aware firewall with geofencing and certificate services using DNS for traffic direction
Answer: A
NEW QUESTION # 205
As part of the customer registration process to access a new bank account, customers are required to upload a number of documents, including their passports and driver's licenses. The process also requires customers to take a current photo of themselves to be compared against provided documentation.
Which of the following BEST describes this process?
- A. Passwordless
- B. Identity proofing
- C. Know your customer
- D. Deepfake
Answer: B
NEW QUESTION # 206
A company's SOC has received threat intelligence about an active campaign utilizing a specific vulnerability.
The company would like to determine whether it is vulnerable to this active campaign.
Which of the following should the company use to make this determination?
- A. A system penetration test
- B. Threat hunting
- C. Log analysis within the SIEM tool
- D. The Cyber Kill Chain
Answer: A
Explanation:
Explanation
The security analyst should remove the cipher TLS_DHE_DSS_WITH_RC4_128_SHA to support the business requirements, as it is considered weak and vulnerable to on-path attacks. RC4 is an outdated stream cipher that has been deprecated by major browsers and protocols due to its flaws and weaknesses. The other ciphers are more secure and compliant with secure-by-design principles and PCI DSS. Verified References:
https://www.comptia.org/blog/what-is-a-cipher
https://partners.comptia.org/docs/default-source/resources/casp-content-guide
NEW QUESTION # 207
A recent data breach revealed that a company has a number of files containing customer data across its storage environment. These files are individualized for each employee and are used in tracking various customer orders, inquiries, and issues. The files are not encrypted and can be accessed by anyone. The senior management team would like to address these issues without interrupting existing processes.
Which of the following should a security architect recommend?
- A. An ERP program to identify which processes need to be tracked
- B. A CRM application to consolidate the data and provision access based on the process and need
- C. A DLP program to identify which files have customer data and delete them
- D. A CMDB to report on systems that are not configured to security baselines
Answer: B
Explanation:
A CRM application is a type of software that helps organizations manage customer relationships and interactions, including storing and organizing customer data. By consolidating the customer data files into a CRM application and implementing proper access controls, the company can ensure that the data is protected and that only authorized employees have access to it.
The security architect should recommend that the CRM application be configured to provision access based on the process and need, so that employees only have access to the data that they need to perform their duties. This can help reduce the risk of unauthorized access to the data and ensure that the data is being used appropriately.
NEW QUESTION # 208
While investigating a security event, an analyst finds evidence that a user opened an email attachment from an unknown source. Shortly after the user opened the attachment, a group of servers experienced a large amount of network and resource activity. Upon investigating the servers, the analyst discovers the servers were encrypted by ransomware that is demanding payment within 48 hours or all data will be destroyed. The company has no response plans for ransomware.
Which of the following is the NEXT step the analyst should take after reporting the incident to the management team?
- A. Request that the affected servers be restored immediately.
- B. Notify law enforcement.
- C. Isolate the servers to prevent the spread.
- D. Pay the ransom within 48 hours.
Answer: C
Explanation:
Isolating the servers is the best immediate action to take after reporting the incident to the management team, as it can limit the damage and contain the ransomware infection. Paying the ransom is not advisable, as it does not guarantee the recovery of the data and may encourage further attacks. Notifying law enforcement is a possible step, but not the next one after reporting. Requesting that the affected servers be restored immediately may not be feasible or effective, as it depends on the availability and integrity of backups, and it does not address the root cause of the attack. Verified Reference: https://www.comptia.org/blog/what-is-ransomware-and-how-to-protect-yourself https://www.comptia.org/certifications/comptia-advanced-security-practitioner
NEW QUESTION # 209
An enterprise is deploying APIs that utilize a private key and a public key to ensure the connection string is protected. To connect to the API, customers must use the private key.
Which of the following would BEST secure the REST API connection to the database while preventing the use of a hard-coded string in the request string?
- A. Deploy MFA for the service accounts.
- B. Implement a VPN for all APIs.
- C. Sign the key with DSA.
- D. Utilize HMAC for the keys.
Answer: D
Explanation:
Utilizing HMAC (hash-based message authentication code) for the keys is the best option for securing the REST API connection to the database while preventing the use of a hard-coded string in the request string. HMAC is a technique that uses a secret key and a hash function to generate a code that can verify the authenticity and integrity of a message, preventing unauthorized modifications or tampering. Utilizing HMAC for the keys can prevent the use of a hard-coded string in the request string, as it can dynamically generate a unique code for each request based on the secret key and the message content, making it difficult to forge or replay. Implementing a VPN (virtual private network) for all APIs is not a good option for securing the REST API connection to the database, as it could introduce latency or performance issues for API requests, as well as not prevent the use of a hard-coded string in the request string. Signing the key with DSA (Digital Signature Algorithm) is not a good option for securing the REST API connection to the database, as it could be vulnerable to attacks or forgery if the key is compromised or weak, as well as not prevent the use of a hard-coded string in the request string. Deploying MFA (multi-factor authentication) for the service accounts is not a good option for securing the REST API connection to the database, as it could affect the usability or functionality of API requests, as well as not prevent the use of a hard-coded string in the request string. Verified Reference: https://www.comptia.org/blog/what-is-hmac https://partners.comptia.org/docs/default-source/resources/casp-content-guide
NEW QUESTION # 210
A business wants to migrate its workloads from an exclusively on-premises IT infrastructure to the cloud but cannot implement all the required controls. Which of the following BEST describes the risk associated with this implementation?
- A. Loss of governance
- B. Vendor lockout
- C. Vendor lock-in
- D. Compliance risk
Answer: D
NEW QUESTION # 211
A security operations center analyst is investigating anomalous activity between a database server and an unknown external IP address and gathered the following data:
- dbadmin last logged in at 7:30 a.m. and logged out at 8:05 a.m.
- A persistent TCP/6667 connection to the external address was
established at 7:55 a.m. The connection is still active.
- Other than bytes transferred to keep the connection alive, only a few kilobytes of data transfer every hour since the start of the connection.
- A sample outbound request payload from PCAP showed the ASCII content:
"JOIN #community".
Which of the following is the MOST likely root cause?
- A. The dbadmin user is consulting the community for help via Internet Relay Chat.
- B. The system has been hijacked for cryptocurrency mining.
- C. A botnet Trojan is installed on the database server.
- D. A SQL injection was used to exfiltrate data from the database server.
Answer: C
NEW QUESTION # 212
A company wants to securely manage the APIs that were developed for its in-house applications.
Previous penetration tests revealed that developers were embedding unencrypted passwords in the code. Which of the following can the company do to address this finding? (Choose two.)
- A. Enforce MFA on the developers' workstations and production systems.
- B. Implement time-based API key management.
- C. Incorporate a DAST into the DevSecOps process to identify the exposure of secrets.
- D. Implement complex, key-length API key management.
- E. Implement user session logging.
- F. Use SOAP instead of restful services.
Answer: A,C
Explanation:
E: Incorporate a DAST (Dynamic Application Security Testing) into the DevSecOps process to identify the exposure of secrets. This will help the company to identify the potential vulnerabilities in the API codes and take necessary measures to address them.
F: Enforce MFA (Multi-Factor Authentication) on the developers' workstations and production systems. This will ensure that the authentication process is more secure and reduce the chances of unencrypted passwords being embedded in the code.
NEW QUESTION # 213
A local university that has a global footprint is undertaking a complete overhaul of its website and associated systems. Some of the requirements are:
* Handle an increase in customer demand of resources
* Provide quick and easy access to information
* Provide high-quality streaming media
* Create a user-friendly interface
Which of the following actions should be taken FIRST?
- A. Deploy high-availability web servers.
- B. Migrate to a virtualized environment.
- C. Enhance network access controls.
- D. Implement a content delivery network.
Answer: D
Explanation:
A content delivery network (CDN) is a geographically distributed network of servers that can cache content close to end users, allowing for faster and more efficient delivery of web content, such as images, videos, and streaming media. A CDN can also handle an increase in customer demand of resources, provide high-quality streaming media, and create a user-friendly interface by reducing latency and bandwidth consumption. A CDN can also improve the security and availability of the website by mitigating DDoS attacks and providing redundancy. Verified References:
https://www.cloudflare.com/learning/cdn/what-is-a-cdn/
https://learn.microsoft.com/en-us/azure/cdn/cdn-overview
https://en.wikipedia.org/wiki/Content_delivery_network
NEW QUESTION # 214
Users are reporting intermittent access issues with a new cloud application that was recently added to the network. Upon investigation, the security administrator notices the human resources department is able to run required queries with the new application, but the marketing department is unable to pull any needed reports on various resources using the new application. Which of the following MOST likely needs to be done to avoid this in the future?
- A. Modify the ACLs.
- B. Reconfigure the WAF.
- C. Update the marketing department's browser.
- D. Review the Active Directory.
Answer: A
Explanation:
Access Control List needs modification for proper access to marketing dept.
NEW QUESTION # 215
Users are claiming that a web server is not accessible. A security engineer logs for the site. The engineer connects to the server and runs netstat -an and receives the following output:
Which of the following is MOST likely happening to the server?
- A. Denial of service
- B. Port scanning
- C. Buffer overflow
- D. ARP spoofing
Answer: A
Explanation:
Explanation
A denial of service (DoS) attack is a malicious attempt to disrupt the normal functioning of a server by overwhelming it with requests or traffic1. One possible indicator of a DoS attack is a large number of connections from a single source IP address1. In this case, the output of netstat -an shows that there are many connections from 213.37.55.67 with different port numbers and in TIME WAIT state23. This suggests that the attacker is sending many SYN packets to initiate connections but not completing them, thus exhausting the server's resources and preventing legitimate users from accessing it1.
NEW QUESTION # 216
A company wants to protect its intellectual property from theft. The company has already applied ACLs and DACs.
Which of the following should the company use to prevent data theft?
- A. Watermarking
- B. DRM
- C. NDA
- D. Access logging
Answer: A
NEW QUESTION # 217
A customer reports being unable to connect to a website at www.test.com to consume services. The customer notices the web application has the following published cipher suite:
Which of the following is the MOST likely cause of the customer's inability to connect?
- A. The public key should be using ECDSA.
- B. The default should be on port 80.
- C. Weak ciphers are being used.
- D. The server name should be test.com.
Answer: A
NEW QUESTION # 218
A pharmaceutical company was recently compromised by ransomware. Given the following EDR output from the process investigation:
On which of the following devices and processes did the ransomware originate?
- A. cpt-ws026, NO-AV.exe
- B. cpt-ws002, NO-AV.exe
- C. cpt-ws018, powershell.exe
- D. cpt-ws002, DearCry.exe
- E. cpt-ws026, DearCry.exe
Answer: A
Explanation:
The EDR output shows the process tree of the ransomware infection. The root node is NO-AV.exe, which is a malicious executable that disables antivirus software and downloads the DearCry ransomware. The NO-AV.exe process was launched on cpt-ws026 by a user named John. The DearCry.exe process was then launched on cpt-ws026 by NO-AV.exe and propagated to other devices via SMB. Therefore, the ransomware originated from cpt-ws026 and NO-AV.exe. Verified References:
https://www.microsoft.com/security/blog/2021/03/12/analyzing-dearcry-ransomware-the-first-attack-to-ex
https://www.crowdstrike.com/blog/dearcry-ransomware-analysis/
NEW QUESTION # 219
A security engineer is reviewing a record of events after a recent data breach incident that Involved the following:
* A hacker conducted reconnaissance and developed a footprint of the company s Internet-facing web application assets.
* A vulnerability in a third-party horary was exploited by the hacker, resulting in the compromise of a local account.
* The hacker took advantage of the account's excessive privileges to access a data store and exfilltrate the data without detection.
Which of the following is the BEST solution to help prevent this type of attack from being successful in the future?
- A. Secure web gateway
- B. Dynamic analysis
- C. User behavior analysis
- D. Software composition analysis
- E. Web application firewall
Answer: A
NEW QUESTION # 220
......
The Ultimate CompTIA CAS-004 Dumps PDF Review: https://www.exam-killer.com/CAS-004-valid-questions.html
Achieve The Utmost Performance In CAS-004 Exam Pass Guaranteed: https://drive.google.com/open?id=1rMToNlsASJaM-Ll34ZmTbH4et9S5f1Mw

