Get 2026 Updated Free CompTIA CAS-004 Exam Questions and Answer
CAS-004 Dumps PDF and Test Engine Exam Questions
Achieving the CompTIA CASP+ certification can lead to a variety of career opportunities, including positions such as security engineer, security architect, security consultant, and cybersecurity manager. CompTIA Advanced Security Practitioner (CASP+) Exam certification also demonstrates to employers and clients that the candidate has the necessary skills and knowledge to implement effective security solutions and manage complex security environments. Overall, the CompTIA CASP+ certification is a valuable asset for security professionals looking to advance their careers and improve their knowledge and skills in the field of cybersecurity.
CompTIA CASP+ certification exam is a challenging and rewarding certification that can help experienced security professionals take their careers to the next level. It covers a wide range of advanced security topics and is designed to test the candidate's ability to solve real-world security problems. CompTIA Advanced Security Practitioner (CASP+) Exam certification is recognized globally and can lead to new job opportunities and higher salaries.
NEW QUESTION # 344
Company A is establishing a contractual with Company B. The terms of the agreement are formalized in a document covering the payment terms, limitation of liability, and intellectual property rights. Which of the following documents will MOST likely contain these elements
- A. Company A-B SLA v2.docx
- B. Company A MSA v3.docx
- C. Company A-B NDA v03.docx
- D. Company A MOU v1.docx
- E. Company A OLA v1b.docx
Answer: A
NEW QUESTION # 345
A penetration tester is conducting an assessment on Comptia.org and runs the following command from a coffee shop while connected to the public Internet:
Which of the following should the penetration tester conclude about the command output?
- A. 192.168.102.67 is a backup mail server that may be more vulnerable to attack
- B. The public/private views on the Comptia.org DNS servers are misconfigured
- C. Comptia.org is running an older mail server, which may be vulnerable to exploits
- D. The DNS SPF records have not been updated for Comptia.org
Answer: B
Explanation:
Answer B is incorrect, there's no information about the server version
Answer C is incorrect, there's no SPF records here
Answer D is incorrect. Usually the secondary MX record is simply a different route to the same server.
Answer A is correct, 192.168.x.x is a private IP address and should not be displayed publicly.
NEW QUESTION # 346
A bank is working with a security architect to find the BEST solution to detect database management system compromises. The solution should meet the following requirements:
* Work at the application layer
* Send alerts on attacks from both privileged and malicious users
* Have a very low false positive
Which of the following should the architect recommend?
- A. DAM
- B. UTM
- C. WAF
- D. NIPS
- E. FIM
Answer: A
NEW QUESTION # 347
A company requires a task to be carried by more than one person concurrently. This is an example of:
- A. job rotation
- B. separation of d duties.
- C. dual control
- D. least privilege
Answer: C
Explanation:
Dual control is a security principle that requires two or more authorized individuals to perform a task concurrently. This reduces the risk of fraud, error, or misuse of sensitive assets or information. Verified Reference: https://www.comptia.org/training/books/casp-cas-004-study-guide , https://www.isaca.org/resources/isaca-journal/issues/2018/volume-1/using-dual-control-to-mitigate-risk
NEW QUESTION # 348
In preparation for the holiday season, a company redesigned the system that manages retail sales and moved it to a cloud service provider. The new infrastructure did not meet the company's availability requirements. During a postmortem analysis, the following issues were highlighted:
1. International users reported latency when images on the web page
were initially loading.
2. During times of report processing, users reported issues with
inventory when attempting to place orders.
3. Despite the fact that ten new API servers were added, the load
across servers was heavy at peak times.
Which of the following infrastructure design changes would be BEST for the organization to implement to avoid these issues in the future?
- A. Serve static content via distributed CDNs, create a read replica of the central database and pull reports from there, and auto-scale API servers based on performance.
- B. Serve images from an object storage bucket with infrequent read times, replicate the database across different regions, and dynamically create API servers based on load.
- C. Serve static-content object storage across different regions, increase the instance size on the managed relational database, and distribute the ten API servers across multiple regions.
- D. Increase the bandwidth for the server that delivers images, use a CDN, change the database to a non-relational database, and split the ten API servers across two load balancers.
Answer: A
Explanation:
This solution would address the three issues as follows:
Serving static content via distributed CDNs would reduce the latency for international users by delivering images from the nearest edge location to the user's request. Creating a read replica of the central database and pulling reports from there would offload the read-intensive workload from the primary database and avoid affecting the inventory data for order placement.
Auto-scaling API servers based on performance would dynamically adjust the number of servers to match the demand and balance the load across them at peak times.
NEW QUESTION # 349
Users are claiming that a web server is not accessible. A security engineer is unable to view the Internet Services logs for the site. The engineer connects to the server and runs netstat - an and receives the following output:
Which of the following is MOST likely happening to the server?
- A. Buffer overflow
- B. Denial of service
- C. ARP spoofing
- D. Port scanning
Answer: B
Explanation:
TCP connections in the TIME_WAIT state, which indicates that there are a lot of connections that are being closed. The large number of TIME_WAIT connections can be an indication that the server is experiencing a Denial of Service (DoS).
NEW QUESTION # 350
After a security incident, a network security engineer discovers that a portion of the company's sensitive external traffic has been redirected through a secondary ISP that is not normally used.
Which of the following would BEST secure the routes while allowing the network to function in the event of a single provider failure?
- A. Disable BGP and implement OSPF.
- B. Implement an inbound BGP prefix list.
- C. Implement a BGP route reflector.
- D. Disable BGP and implement a single static route for each internal network.
Answer: B
Explanation:
Explanation
Defenses against BGP hijacks include IP prefix filtering, meaning IP address announcements are sent and accepted only from a small set of well-defined autonomous systems, and monitoring Internet traffic to identify signs of abnormal traffic flows.
NEW QUESTION # 351
A security analyst notices a number of SIEM events that show the following activity:
Which of the following response actions should the analyst take FIRST?
- A. Configure the forward proxy to block 40.90.23.154.
- B. Disable local administrator privileges on the endpoints.
- C. Disable powershell.exe on all Microsoft Windows endpoints.
- D. Restart Microsoft Windows Defender.
Answer: A
Explanation:
Explanation
The SIEM events show that powershell.exe was executed on multiple endpoints with an outbound connection to 40.90.23.154, which is an IP address associated with malicious activity. This could indicate a malware infection or a command-and-control channel. The best response action is to configure the forward proxy to block 40.90.23.154, which would prevent further communication with the malicious IP address. Disabling powershell.exe on all endpoints may not be feasible or effective, as it could affect legitimate operations and not remove the malware. Restarting Microsoft Windows Defender may not detect or stop the malware, as it could have bypassed or disabled it. Disabling local administrator privileges on the endpoints may not prevent the malware from running or communicating, as it could have escalated privileges or used other methods.
Verified References: https://www.comptia.org/blog/what-is-a-forward-proxy
https://partners.comptia.org/docs/default-source/resources/casp-content-guide
NEW QUESTION # 352
A business stores personal client data of individuals residing in the EU in order to process requests for mortgage loan approvals.
Which of the following does the business's IT manager need to consider?
- A. The right to personal data erasure
- B. The availability of personal data
- C. The language of the web application
- D. The company's annual revenue
Answer: A
Explanation:
Reference: https://gdpr.eu/right-to-be-forgotten/#:~:text=Also%20known%20as%20the%20right,to%
20delete%20their%20personal%20data.&text=The%20General%20Data%20Protection%20Regulation, collected%2C%20processed%2C%20and%20erased The right to personal data erasure, also known as the right to be forgotten, is one of the requirements of the EU General Data Protection Regulation (GDPR), which applies to any business that stores personal data of individuals residing in the EU. This right allows individuals to request the deletion of their personal data from a business under certain circumstances. The availability of personal data, the company's annual revenue, and the language of the web application are not relevant to the GDPR. Verified References: https://www.comptia.
org/blog/what-is-gdpr https://partners.comptia.org/docs/default-source/resources/casp-content-guide
NEW QUESTION # 353
A security technician is trying to connect a remote site to the central office over a site-to-site VPN. The technician has verified the source and destination IP addresses are correct, but the technician is unable to get the remote site to connect. The following error message keeps repeating:
"An error has occurred during Phase 1 handshake. Deleting keys and retrying..." Which of the following is most likely the reason the connection is failing?
- A. The Diffie-Hellman group on both sides matches but is a legacy group.
- B. The IKE hashing algorithm uses different key lengths on each VPN device.
- C. The remote VPN is attempting to connect with a protocol other than SSL/TLS.
- D. The IPSec settings allow more than one cipher suite on both devices.
Answer: B
Explanation:
TheIKE (Internet Key Exchange)Phase 1 handshake error indicates a failure in negotiating a secure connection.
Option A:The IKE hashing algorithm mismatch, including key lengths, often causes such failures. Both VPN devices must agree on compatible algorithms and key lengths for the handshake to succeed.
Option B:Multiple cipher suites do not inherently cause errors; they provide flexibility during negotiation.
Option C:While using a legacy Diffie-Hellman group is less secure, it does not typically cause the handshake to fail unless explicitly rejected.
Option D:Site-to-site VPNs do not use SSL/TLS; they rely on IPSec protocols, making this irrelevant.
Reference:
CompTIA CASP+ Exam Objective 2.2: Implement network security solutions, including VPN configurations.
CASP+ Study Guide, 5th Edition, Chapter 7, VPN Technologies and Troubleshooting.
NEW QUESTION # 354
An organization is assessing the security posture of a new SaaS CRM system that handles sensitive Pll and identity information, such as passport numbers. The SaaS CRM system does not meet the organization's current security standards. The assessment identifies the following:
1) There will be a $20,000 per day revenue loss for each day the system is delayed going into production.
2) The inherent risk is high.
3) The residual risk is low.
4) There will be a staged deployment to the solution rollout to the contact center.
Which of the following risk-handling techniques will BEST meet the organization's requirements?
- A. Avoid the risk by accepting the shared responsibility model with the SaaS CRM provider.
- B. Transfer the risk to the SaaS CRM vendor, as the organization is using a cloud service.
- C. Accept the risk, as compensating controls have been implemented to manage the risk.
- D. Apply for a security exemption, as the risk is too high to accept.
Answer: A
NEW QUESTION # 355
A company created an external application for its customers. A security researcher now reports that the application has a serious LDAP injection vulnerability that could be leveraged to bypass authentication and authorization.
Which of the following actions would BEST resolve the issue? (Choose two.)
- A. Deploy a WAF.
- B. Deploy a SIEM.
- C. Patch the OS
- D. Deploy an IDS.
- E. Use containers.
- F. Deploy a reverse proxy
- G. Conduct input sanitization.
Answer: A,G
Explanation:
Explanation
A WAF protects your web apps by filtering, monitoring, and blocking any malicious HTTP/S traffic traveling to the web application, and prevents any unauthorized data from leaving the app. It does this by adhering to a set of policies that help determine what traffic is malicious and what traffic is safe.
NEW QUESTION # 356
A security analyst discovered that the company's WAF was not properly configured. The main web server was breached, and the following payload was found in one of the malicious requests:
Which of the following would BEST mitigate this vulnerability?
- A. CAPTCHA
- B. Data encoding
- C. Input validation
- D. Network intrusion prevention
Answer: C
NEW QUESTION # 357
An organization has an operational requirement with a specific equipment vendor The organization is located in the United States, but the vendor is located in another region Which of the following risks would be most concerning to the organization in the event of equipment failure?
- A. Support may not be available during all business hours
- B. Each region has different regulatory frameworks to follow
- C. The organization requires authorized vendor specialists.
- D. Shipping delays could cost the organization money
Answer: A
Explanation:
The primary risk for an organization working with vendors in different time zones is that support might not be available during the organization's regular business hours. This can lead to delays in receiving necessary support or assistance when equipment issues arise, which could be critical if there's an equipment failure.
NEW QUESTION # 358
A SaaS startup is maturing its DevSecOps program and wants to identify weaknesses earlier in the development process in order to reduce the average time to identify serverless application vulnerabilities and the costs associated with remediation. The startup began its early security testing efforts with DAST to cover public-facing application components and recently implemented a bug bounty program. Which of the following will BEST accomplish the company's objectives? (Choose two.)
- A. CMS
- B. IAST
- C. SAST
- D. WAF
- E. SCA
- F. RASP
Answer: B,C
NEW QUESTION # 359
You are a security analyst tasked with interpreting an Nmap scan output from company's privileged network.
The company's hardening guidelines indicate the following:
There should be one primary server or service per device.
Only default ports should be used.
Non-secure protocols should be disabled.
INSTRUCTIONS
Using the Nmap output, identify the devices on the network and their roles, and any open ports that should be closed.
For each device found by Nmap, add a device entry to the Devices Discovered list, with the following information:
The IP address of the device
The primary server or service of the device (Note that each IP should by associated with one service/port only) The protocol(s) that should be disabled based on the hardening guidelines (Note that multiple ports may need to be closed to comply with the hardening guidelines) If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Answer:
Explanation:
See explanation below.
Explanation:
10.1.45.65 SFTP Server Disable 8080
10.1.45.66 Email Server Disable 415 and 443
10.1.45.67 Web Server Disable 21, 80
10.1.45.68 UTM Appliance Disable 21
NEW QUESTION # 360
A security analyst is reviewing the following output:
Which of the following would BEST mitigate this type of attack?
- A. Implementing an IDS
- B. Deploying a honeypot
- C. Installing a network firewall
- D. Placing a WAF inline
Answer: D
Explanation:
Explanation
The output shows a SQL injection attack that is trying to exploit a web application. A WAF (Web Application Firewall) is a security solution that can detect and block malicious web requests, such as SQL injection, XSS, CSRF, etc. Placing a WAF inline would prevent the attack from reaching the web server and database.
References: https://owasp.org/www-community/attacks/SQL_Injection
https://www.cloudflare.com/learning/ddos/glossary/web-application-firewall-waf/
NEW QUESTION # 361
An analyst received a list of IOCs from a government agency. The attack has the following characteristics:
1. The attack starts with bulk phishing.
2. If a user clicks on the link, a dropper is downloaded to the computer.
3. Each of the malware samples has unique hashes tied to the user.
The analyst needs to identify whether existing endpoint controls are effective. Which of the following risk mitigation techniques should the analyst use?
- A. Detonate in a sandbox.
- B. Update the incident response plan.
- C. Blocklist the executable.
- D. Deploy a honeypot onto the laptops.
Answer: A
Explanation:
Detonating the malware in a sandbox is the best way to analyze its behavior and determine whether the existing endpoint controls are effective. A sandbox is an isolated environment that mimics a real system but prevents any malicious actions from affecting the actual system. By detonating the malware in a sandbox, the analyst can observe how it interacts with the system, what files it creates or modifies, what network connections it establishes, and what indicators of compromise it exhibits. This can help the analyst identify the malware's capabilities, objectives, and weaknesses. A sandbox can also help the analyst compare different malware samples and determine if they are related or part of the same campaign.
A) Updating the incident response plan is not a risk mitigation technique, but rather a proactive measure to prepare for potential incidents. It does not help the analyst identify whether existing endpoint controls are effective against the malware.
B) Blocklisting the executable is a risk mitigation technique that can prevent the malware from running on the system, but it does not help the analyst analyze its behavior or determine whether existing endpoint controls are effective. Moreover, blocklisting may not be feasible if each malware sample has a unique hash tied to the user.
C) Deploying a honeypot onto the laptops is a risk mitigation technique that can lure attackers away from the real systems and collect information about their activities, but it does not help the analyst analyze the malware's behavior or determine whether existing endpoint controls are effective. A honeypot is also more suitable for detecting network-based attacks rather than endpoint-based attacks.
NEW QUESTION # 362
......
Verified CAS-004 exam dumps Q&As with Correct 620 Questions and Answers: https://www.exam-killer.com/CAS-004-valid-questions.html
Get New CAS-004 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1l4mu-whxzjzjStU-9KS2SqnY4G1Fyugs

