COMPTIA CASP+ Exam CAS-004 Questions V9.02 CompTIA CASP+ Topics - CompTIA Advanced Security Practitioner (CASP+) Exam Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First 1.A company suspects a web server may have been infiltrated by a rival corporation. The security engineer reviews the web server logs and finds the following: The security engineer looks at the code with a developer, and they determine the log entry is created when the following line is run: Which of the following is an appropriate security control the company should implement? A. Restrict directory permission to read-only access. B. Use server-side processing to avoid XSS vulnerabilities in path input. C. Separate the items in the system call to prevent command injection. D. Parameterize a query in the path variable to prevent SQL injection. Answer: C 2. An organization wants to perform a scan of all its systems against best practice security configurations. Which of the following SCAP standards, when combined, will enable the organization to view each of the configuration checks in a machine-readable checklist format for fill automation? (Choose two.) A. ARF B. XCCDF C. CPE D. CVE E. CVSS F. OVAL Answer: B,F Explanation: Reference: https://www.govinfo.gov/content/pkg/GOVPUB-C13-9ecd8eae582935c93 d7f410e955dabb6/pdf/GOVPUB-C13-9ecd8eae582935c93d7f410e955dabb6.pdf (p.12) 3. Immediately following the report of a potential breach, a security engineer creates a forensic image of the server in question as part of the organization incident response procedure . Which of the must occur to ensure the integrity of the image? A. The image must be password protected against changes. B. A hash value of the image must be computed. Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First C. The disk containing the image must be placed in a seated container. D. A duplicate copy of the image must be maintained Answer: B 4. A security auditor needs to review the manner in which an entertainment device operates. The auditor is analyzing the output of a port scanning tool to determine the next steps in the security review. Given the following log output. The best option for the auditor to use NEXT is: A. A SCAP assessment. B. Reverse engineering C. Fuzzing D. Network interception. Answer: A 5. A security engineer estimates the company’s popular web application experiences 100 attempted breaches per day. In the past four years, the company’s data has been breached two times. Which of the following should the engineer report as the ARO for successful breaches? A. 0.5 B. 8 C. 50 D. 36,500 Answer: A Explanation: Reference: https://blog.netwrix.com/2020/07/24/annual-loss-expectancy-and- quantitative-risk-analysis/ 6. A company provides guest WiFi access to the internet and physically separates the Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First guest network from the company’s internal WIFI. Due to a recent incident in which an attacker gained access to the compay’s intend WIFI, the company plans to configure WPA2 Enterprise in an EAP- TLS configuration . Which of the following must be installed on authorized hosts for this new configuration to work properly? A. Active Directory OPOs B. PKI certificates C. Host-based firewall D. NAC persistent agent Answer: B 7. Due to locality and budget constraints, an organization’s satellite office has a lower bandwidth allocation than other offices in the organization. As a result, the local security infrastructure staff is assessing architectural options that will help preserve network bandwidth and increase speed to both internal and external resources while not sacrificing threat visibility. Which of the following would be the BEST option to implement? A. Distributed connection allocation B. Local caching C. Content delivery network D. SD-WAN vertical heterogeneity Answer: C 8. Which of the following technologies allows CSPs to add encryption across multiple data storages? A. Symmetric encryption B. Homomorphic encryption C. Data dispersion D. Bit splitting Answer: A Explanation: Reference: https://www.hhs.gov/sites/default/files/nist800111.pdf 9. A company undergoing digital transformation is reviewing the resiliency of a CSP and is concerned about meeting SLA requirements in the event of a CSP incident. Which of the following would be BEST to proceed with the transformation? A. An on-premises solution as a backup B. A load balancer with a round-robin configuration C. A multicloud provider solution D. An active-active solution within the same tenant Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First Answer: D 10. A security architect is reviewing the following proposed corporate firewall architecture and configuration: Both firewalls are stateful and provide Layer 7 filtering and routing. The company has the following requirements: Web servers must receive all updates via HTTP/S from the corporate network. Web servers should not initiate communication with the Internet. Web servers should only connect to preapproved corporate database servers. Employees’ computing devices should only connect to web services over ports 80 and 443. Which of the following should the architect recommend to ensure all requirements are met in the MOST secure manner? (Choose two.) A. Add the following to Firewall_A: 15 PERMIT FROM 10.0.0.0/16 TO 0.0.0.0/0 TCP 80,443 B. Add the following to Firewall_A: 15 PERMIT FROM 192.168.1.0/24 TO 0.0.0.0 TCP 80,443 C. Add the following to Firewall_A: 15 PERMIT FROM 10.0.0.0/16 TO 0.0.0.0/0 TCP/UDP 0-65535 D. Add the following to Firewall_B: 15 PERMIT FROM 0.0.0.0/0 TO 10.0.0.0/16 TCP/UDP 0-65535 E. Add the following to Firewall_B: 15 PERMIT FROM 10.0.0.0/16 TO 0.0.0.0 TCP/UDP 0-65535 F. Add the following to Firewall_B: 15 PERMIT FROM 192.168.1.0/24 TO 10.0.2.10/32 TCP 80,443 Answer: A,D 11. A security compliance requirement states that specific environments that handle sensitive data must be protected by need-to-know restrictions and can only connect to authorized endpoints. The requirement also states that a DLP solution within the environment must be used to control the data from leaving the environment. Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First Which of the following should be implemented for privileged users so they can support the environment from their workstations while remaining compliant? A. NAC to control authorized endpoints B. FIM on the servers storing the data C. A jump box in the screened subnet D. A general VPN solution to the primary network Answer: D 12. An organization recently experienced a ransomware attack. The security team leader is concerned about the attack reoccurring . Howe ver, no further security measures have been implemented. Which of the following processes can be used to identify potential prevention recommendations? A. Detection B. Remediation C. Preparation D. Recovery Answer: A 13. A financial services company wants to migrate its email services from on- premises servers to a cloud-based email solution. The Chief information Security Officer (CISO) must brief board of directors on the potential security concerns related to this migration. The board is concerned about the following. * Transactions being required by unauthorized individual * Complete discretion regarding client names, account numbers, and investment information. * Malicious attacker using email to distribute malware and ransom ware. * Exfiltration of sensitivity company information. The cloud-based email solution will provide an6-malware, reputation-based scanning, signature-based scanning, and sandboxing . Which of the following is the BEST option to resolve the board’s concerns for this email migration? A. Data loss prevention B. Endpoint detection response C. SSL VPN D. Application whitelisting Answer: A 14. The Chief information Officer (CIO) wants to establish a non-banding agreement Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First with a third party that outlines the objectives of the mutual arrangement dealing with data transfers between both organizations before establishing a format partnership . Which of the follow would MOST likely be used? A. MOU B. OLA C. NDA D. SLA Answer: A 15. An organization developed a social media application that is used by customers in multiple remote geographic locations around the world. The organization’s headquarters and only datacenter are located in New York City. The Chief Information Security Officer wants to ensure the following requirements are met for the social media application: Low latency for all mobile users to improve the users’ experience SSL offloading to improve web server performance Protection against DoS and DDoS attacks High availability Which of the following should the organization implement to BEST ensure all requirements are met? A. A cache server farm in its datacenter B. A load-balanced group of reverse proxy servers with SSL acceleration C. A CDN with the origin set to its datacenter D. Dual gigabit-speed Internet connections with managed DDoS prevention Answer: B 16. A home automation company just purchased and installed tools for its SOC to enable incident identification and response on software the company develops. The company would like to prioritize defenses against the following attack scenarios: Unauthorized insertions into application development environments Authorized insiders making unauthorized changes to environment configurations Which of the following actions will enable the data feeds needed to detect these types of attacks on development environments? (Choose two.) A. Perform static code analysis of committed code and generate summary reports. B. Implement an XML gateway and monitor for policy violations. C. Monitor dependency management tools and report on susceptible third-party libraries. D. Install an IDS on the development subnet and passively monitor for vulnerable services. E. Model user behavior and monitor for deviations from normal. F. Continuously monitor code commits to repositories and generate summary logs. Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First Answer: C,D 17. A company’s SOC has received threat intelligence about an active campaign utilizing a specific vulnerability. The company would like to determine whether it is vulnerable to this active campaign. Which of the following should the company use to make this determination? A. Threat hunting B. A system penetration test C. Log analysis within the SIEM tool D. The Cyber Kill Chain Answer: B 18. DRAG DROP An organization is planning for disaster recovery and continuity of operations. INSTRUCTIONS Review the following scenarios and instructions. Match each relevant finding to the affected host. After associating scenario 3 with the appropriate host(s), click the host to select the appropriate corrective action for that finding. Each finding may be used more than once. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First Answer: Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First 19. A Chief information Security Officer (CISO) has launched to create a rebuts BCP/DR plan for the entire company. As part of the initiative, the security team must gather data supporting s operational importance for the applications used by the business and determine the order in which the application must be back online . Which of the following be the FIRST step taken by the team? A. Perform a review of all policies an procedures related to BGP a and DR and created an educated educational module that can be assigned to at employees to provide training on BCP/DR events. B. Create an SLA for each application that states when the application will come back online and distribute this information to the business units. C. Have each business unit conduct a BIA and categories the application according to the cumulative data gathered. D. Implement replication of all servers and application data to back up detacenters that are geographically from the central datacenter and release an upload BPA to all clients. Answer: C 20. A company is preparing to deploy a global service. Which of the following must the company do to ensure GDPR compliance? (Choose two.) A. Inform users regarding what data is stored. B. Provide opt-in/out for marketing messages. C. Provide data deletion capabilities. D. Provide optional data encryption. E. Grant data access to third parties. F. Provide alternative authentication techniques. Answer: A,B Explanation: Reference: https://gdpr.eu/compliance-checklist-us-companies/ 21. A university issues badges through a homegrown identity management system to all staff and students. Each week during the summer, temporary summer school students arrive and need to be issued a badge to access minimal campus resources. The security team received a report from an outside auditor indicating the homegrown system is not consistent with best practices in the security field and leaves the institution vulnerable. Which of the following should the security team recommend FIRST? A. Investigating a potential threat identified in logs related to the identity management system B. Updating the identity management system to use discretionary access control C. Beginning research on two-factor authentication to later introduce into the identity Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First management system D. Working with procurement and creating a requirements document to select a new IAM system/vendor Answer: A 22. A business stores personal client data of individuals residing in the EU in order to process requests for mortgage loan approvals. Which of the following does the business’s IT manager need to consider? A. The availability of personal data B. The right to personal data erasure C. The company’s annual revenue D. The language of the web application Answer: B Explanation: Reference: https://gdpr.eu/right-to-be-forgotten/#:~:text=Also known as the right,to delete their personal data.&text=The General Data Protection Regulation,collected%2C processed%2C and erased 23. A cybersecurity engineer analyst a system for vulnerabilities. The tool created an OVAL. Results document as output . Which of the following would enable the engineer to interpret the results in a human readable form? (Select TWO.) A. Text editor B. OOXML editor C. Event Viewer D. XML style sheet E. SCAP tool F. Debugging utility Answer: A,E 24. All staff at a company have started working remotely due to a global pandemic. To transition to remote work, the company has migrated to SaaS collaboration tools. The human resources department wants to use these tools to process sensitive information but is concerned the data could be: Leaked to the media via printing of the documents Sent to a personal email address Accessed and viewed by systems administrators Uploaded to a file storage site Which of the following would mitigate the department’s concerns? A. Data loss detection, reverse proxy, EDR, and PGP Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First B. VDI, proxy, CASB, and DRM C. Watermarking, forward proxy, DLP, and MFA D. Proxy, secure VPN, endpoint encryption, and AV Answer: B 25. A company plans to build an entirely remote workforce that utilizes a cloud-based infrastructure. The Chief Information Security Officer asks the security engineer to design connectivity to meet the following requirements: Only users with corporate-owned devices can directly access servers hosted by the cloud provider. The company can control what SaaS applications each individual user can access. User browser activity can be monitored. Which of the following solutions would BEST meet these requirements? A. IAM gateway, MDM, and reverse proxy B. VPN, CASB, and secure web gateway C. SSL tunnel, DLP, and host-based firewall D. API gateway, UEM, and forward proxy Answer: B 26. After a security incident, a network security engineer discovers that a portion of the company’s sensitive external traffic has been redirected through a secondary ISP that is not normally used. Which of the following would BEST secure the routes while allowing the network to function in the event of a single provider failure? A. Disable BGP and implement a single static route for each internal network. B. Implement a BGP route reflector. C. Implement an inbound BGP prefix list. D. Disable BGP and implement OSPF. Answer: B 27. A company that uses AD is migrating services from LDAP to secure LDAP. During the pilot phase, services are not connecting properly to secure LDAP. Block is an except of output from the troubleshooting session: Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First Which of the following BEST explains why secure LDAP is not working? (Select TWO.) A. The clients may not trust idapt by default. B. The secure LDAP service is not started, so no connections can be made. C. Danvills.com is under a DDoS-inator attack and cannot respond to OCSP requests. D. Secure LDAP should be running on UDP rather than TCP. E. The company is using the wrong port. It should be using port 389 for secure LDAP. F. Secure LDAP does not support wildcard certificates. G. The clients may not trust Chicago by default. Answer: B,E 28. A security is assisting the marketing department with ensuring the security of the organization’s social media platforms. The two main concerns are: The Chief marketing officer (CMO) email is being used department wide as the username The password has been shared within the department Which of the following controls would be BEST for the analyst to recommend? A. Configure MFA for all users to decrease their reliance on other authentication. B. Have periodic, scheduled reviews to determine which OAuth configuration are set for each media platform. C. Create multiple social media accounts for all marketing user to separate their actions. D. Ensue the password being shared is sufficiently and not written down anywhere. Answer: A 29. A company is looking for a solution to hide data stored in databases. The solution must meet the following requirements: Be efficient at protecting the production environment Not require any change to the application Act at the presentation layer Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First Which of the following techniques should be used? A. Masking B. Tokenization C. Algorithmic D. Random substitution Answer: A 30. A security analyst receives an alert from the SIEM regarding unusual activity on an authorized public SSH jump server. To further investigate, the analyst pulls the event logs directly from /var/log/auth.log: graphic.ssh_auth_log. Which of the following actions would BEST address the potential risks by the activity in the logs? A. Alerting the misconfigured service account password B. Modifying the AllowUsers configuration directive C. Restricting external port 22 access D. Implementing host-key preferences Answer: C Explanation: Reference: https://www.rapid7.com/blog/post/2017/10/04/how-to-secure-ssh-server- using-port-knocking-on-ubuntu-linux/ 31. Which of the following are risks associated with vendor lock-in? (Choose two.) A. The client can seamlessly move data. B. The vendor can change product offerings. C. The client receives a sufficient level of service. D. The client experiences decreased quality of service. E. The client can leverage a multicloud approach. F. The client experiences increased interoperability. Answer: B,D Explanation: Reference: https://www.cloudflare.com/learning/cloud/what-is-vendor-lock- in/#:~:text=Vendor lock%2Din can become,may involve reformatting%2 0the data 32. A security engineer was auditing an organization’s current software development practice and discovered that multiple open-source libraries were Integrated into the organization’s software. The organization currently performs SAST and DAST on the software it develops. Which of the following should the organization incorporate into the SDLC to ensure the security of the open-source libraries? A. Perform additional SAST/DAST on the open-source libraries. Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First B. Implement the SDLC security guidelines. C. Track the library versions and monitor the CVE website for related vulnerabilities. D. Perform unit testing of the open-source libraries. Answer: B Explanation: Reference: https://www.whitesourcesoftware.com/resources/blog/application-security- best-practices/ 33. A security engineer has been asked to close all non-secure connections from the corporate network. The engineer is attempting to understand why the corporate UTM will not allow users to download email via IMAPS. The engineer formulates a theory and begins testing by creating the firewall ID 58, and users are able to download emails correctly by using IMAP instead. The network comprises three VLANs: The security engineer looks at the UTM firewall rules and finds the following: Which of the following should the security engineer do to ensure IMAPS functions properly on the corporate user network? A. Contact the email service provider and ask if the company IP is blocked. B. Confirm the email server certificate is installed on the corporate computers. C. Make sure the UTM certificate is imported on the corporate computers. D. Create an IMAPS firewall rule to ensure email is allowed. Answer: C 34. Which of the following is the MOST important security objective when applying cryptography to control messages that tell an ICS how much electrical power to output? Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First A. Importing the availability of messages B. Ensuring non-repudiation of messages C. Enforcing protocol conformance for messages D. Assuring the integrity of messages Answer: D 35. Company A is establishing a contractual with Company B. The terms of the agreement are formalized in a document covering the payment terms, limitation of liability, and intellectual property rights . Which of the following documents will MOST likely contain these elements? A. Company A-B SLA v2.docx B. Company A OLA v1b.docx C. Company A MSA v3.docx D. Company A MOU v1.docx E. Company A-B NDA v03.docx Answer: A 36. An application server was recently upgraded to prefer TLS 1.3, and now users are unable to connect their clients to the server. Attempts to reproduce the error are confirmed, and clients are reporting the following: ERR_SSL_VERSION_OR_CIPHER_MISMATCH Which of the following is MOST likely the root cause? A. The client application is testing PFS. B. The client application is configured to use ECDHE. C. The client application is configured to use RC4. D. The client application is configured to use AES-256 in GCM. Answer: C Explanation: Reference: https://kinsta.com/knowledgebase/err_ssl_version_or_cipher_mismatch/ 37. A security architect for a large, multinational manufacturer needs to design and implement a security solution to monitor traffic. When designing the solution, which of the following threats should the security architect focus on to prevent attacks against the network? A. Packets that are the wrong size or length B. Use of any non-DNP3 communication on a DNP3 port C. Multiple solicited responses over time D. Application of an unsupported encryption algorithm Answer: C Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First 38. An organization is prioritizing efforts to remediate or mitigate risks identified during the latest assessment. For one of the risks, a full remediation was not possible, but the organization was able to successfully apply mitigations to reduce the likelihood of impact. Which of the following should the organization perform NEXT? A. Assess the residual risk. B. Update the organization’s threat model. C. Move to the next risk in the register. D. Recalculate the magnitude of impact. Answer: D 39. A cybersecurity analyst receives a ticket that indicates a potential incident is occurring. There has been a large in log files generated by a generated by a website containing a ‘’Contact US’’ form. The analyst must determine if the increase in website traffic is due to a recent marketing campaign of if this is a potential incident . Which of the following would BEST assist the analyst? A. Ensuring proper input validation is configured on the ‘’Contact US’’ form B. Deploy a WAF in front of the public website C. Checking for new rules from the inbound network IPS vendor D. Running the website log files through a log reduction and analysis tool Answer: D 40. A security analyst is reading the results of a successful exploit that was recently conducted by third-party penetration testers. The testers reverse engineered a privileged executable. In the report, the planning and execution of the exploit is detailed using logs and outputs from the test However, the attack vector of the exploit is missing, making it harder to recommend remediation’s. Given the following output: Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First The penetration testers MOST likely took advantage of: A. A TOC/TOU vulnerability B. A plain-text password disclosure C. An integer overflow vulnerability D. A buffer overflow vulnerability Answer: A 41. A company in the financial sector receives a substantial number of customer transaction requests via email. While doing a root-cause analysis conceding a security breach, the CIRT correlates an unusual spike in port 80 traffic from the IP address of a desktop used by a customer relations employee who has access to several of the compromised accounts. Subsequent antivirus scans of the device do not return an findings, but the CIRT finds undocumented services running on the device . Which of the following controls would reduce the discovery time for similar in the future. Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First A. Implementing application blacklisting B. Configuring the mall to quarantine incoming attachment automatically C. Deploying host-based firewalls and shipping the logs to the SIEM D. Increasing the cadence for antivirus DAT updates to twice daily Answer: C 42. A cybersecurity analyst created the following tables to help determine the maximum budget amount the business can justify spending on an improved email filtering system: Which of the following meets the budget needs of the business? A. Filter ABC B. Filter XYZ C. Filter GHI D. Filter TUV Answer: C 43. A security analyst is reviewing network connectivity on a Linux workstation and examining the active TCP connections using the command line. Which of the following commands would be the BEST to run to view only active Internet connections? A. sudo netstat -antu | grep “LISTEN” | awk ‘{print$5}’ B. sudo netstat -nlt -p | grep “ESTABLISHED” C. sudo netstat -plntu | grep -v “Foreign Address” D. sudo netstat -pnut -w | column -t -s $’\w’ E. sudo netstat -pnut | grep -P ^tcp Free CompTIA CAS-004 Demo PDF [2022] Check CAS-004 Exam Questions First Answer: B Explanation: Reference: https://www.codegrepper.com/code-examples/shell/netstat+find+port 44. A security analyst is reviewing the following output: Which of the following would BEST mitigate this type of attack? A. Installing a network firewall B. Placing a WAF inline C. Implementing an IDS D. Deploying a honeypot Answer: A 45. An organization recently started processing, transmitting, and storing its customers’ credit card information. Within a week of doing so, the organization suffered a massive breach that resulted in the exposure of the customers’ information. Which of the following provides the BEST guidance for protecting such information while it is at rest and in transit? A. NIST B. GDPR C. PCI DSS D. ISO Answer: C Explanation: Reference: https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard