Exam Code: CAS-004 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: CompTIA Advanced Security Practitioner (CASP+) Exam
Certification Provider: CompTIA
Free Today! Guaranteed Training- Pass CAS-004 Exam.

Online CompTIA CAS-004 free dumps demo Below:

NEW QUESTION 1
A small company needs to reduce its operating costs. vendors have proposed solutions, which all focus on management of the company’s website and services. The Chief information Security Officer (CISO) insist all available resources in the proposal must be dedicated, but managing a private cloud is not an option .
Which of the following is the BEST solution for this company?

  • A. Community cloud service model
  • B. Multinency SaaS
  • C. Single-tenancy SaaS
  • D. On-premises cloud service model

Answer: A

NEW QUESTION 2
Which of the following terms refers to the delivery of encryption keys to a CASB or a third-party entity?

  • A. Key sharing
  • B. Key distribution
  • C. Key recovery
  • D. Key escrow

Answer: B

Explanation:
Reference: https://www.open.edu/openlearn/ocw/mod/oucontent/view.php?id=48322§ion=1.3

NEW QUESTION 3
An organization is preparing to migrate its production environment systems from an on-premises environment to a cloud service. The lead security architect is concerned that the organization's current methods for addressing risk may not be possible in the cloud environment.
Which of the following BEST describes the reason why traditional methods of addressing risk may not be possible in the cloud?

  • A. Migrating operations assumes the acceptance of all risk.
  • B. Cloud providers are unable to avoid risk.
  • C. Specific risks cannot be transferred to the cloud provider.
  • D. Risks to data in the cloud cannot be mitigated.

Answer: C

Explanation:
Reference: https://arxiv.org/ftp/arxiv/papers/1303/1303.4814.pdf

NEW QUESTION 4
A business stores personal client data of individuals residing in the EU in order to process requests for mortgage loan approvals. Which of the following does the business’s IT manager need to consider?

  • A. The availability of personal data
  • B. The right to personal data erasure
  • C. The company’s annual revenue
  • D. The language of the web application

Answer: B

Explanation:
Reference: https://gdpr.eu/right-to-beforgotten/#:~:text=Also%20known%20as%20the%20right,to%20delete%20their%20personal%20data.&text=The%20General%20Data%20Protection%20Regulation,collected%2C%20processed%2C%20and%20erased

NEW QUESTION 5
An analyst execute a vulnerability scan against an internet-facing DNS server and receives the
following report:
CAS-004 dumps exhibit
Which of the following tools should the analyst use FIRST to validate the most critical vulnerability?

  • A. Password cracker
  • B. Port scanner
  • C. Account enumerator
  • D. Exploitation framework

Answer: A

NEW QUESTION 6
An organization wants to perform a scan of all its systems against best practice security configurations.
Which of the following SCAP standards, when combined, will enable the organization to view each of the configuration checks in a machine-readable checklist format for fill automation? (Choose two.)

  • A. ARF
  • B. XCCDF
  • C. CPE
  • D. CVE
  • E. CVSS
  • F. OVAL

Answer: BF

Explanation:
Reference: https://www.govinfo.gov/content/pkg/GOVPUB-C13-9ecd8eae582935c93d7f410e955dabb6/pdf/GOVPUB-C13-9ecd8eae582935c93d7f410e955dabb6.pdf (p.12)

NEW QUESTION 7
A security analyst notices a number of SIEM events that show the following activity:
CAS-004 dumps exhibit
Which of the following response actions should the analyst take FIRST?

  • A. Disable powershell.exe on all Microsoft Windows endpoints.
  • B. Restart Microsoft Windows Defender.
  • C. Configure the forward proxy to block 40.90.23.154.
  • D. Disable local administrator privileges on the endpoints.

Answer: A

NEW QUESTION 8
A customer reports being unable to connect to a website at www.test.com to consume services. The customer notices the web application has the following published cipher suite:
CAS-004 dumps exhibit
Which of the following is the MOST likely cause of the customer’s inability to connect?

  • A. Weak ciphers are being used.
  • B. The public key should be using ECDSA.
  • C. The default should be on port 80.
  • D. The server name should be test.com.

Answer: B

Explanation:
Reference: https://security.stackexchange.com/questions/23383/ssh-key-type-rsa-dsa-ecdsa-are-there-easy-answers-forwhich-to-choose-when

NEW QUESTION 9
A small business requires a low-cost approach to theft detection for the audio recordings it produces and sells. Which of the following techniques will MOST likely meet the business’s needs?

  • A. Performing deep-packet inspection of all digital audio files
  • B. Adding identifying filesystem metadata to the digital audio files
  • C. Implementing steganography
  • D. Purchasing and installing a DRM suite

Answer: C

Explanation:
Reference: https://portswigger.net/daily-swig/what-is-steganography-a-complete-guide-to-the-ancient-art-of-concealingmessages
CAS-004 dumps exhibit

NEW QUESTION 10
A Chief Information Officer is considering migrating all company data to the cloud to save money on expensive SAN storage. Which of the following is a security concern that will MOST likely need to be addressed during migration?

  • A. Latency
  • B. Data exposure
  • C. Data loss
  • D. Data dispersion

Answer: A

NEW QUESTION 11
Which of the following allows computation and analysis of data within a ciphertext without knowledge of the plaintext?

  • A. Lattice-based cryptography
  • B. Quantum computing
  • C. Asymmetric cryptography
  • D. Homomorphic encryption

Answer: C

Explanation:
Reference: https://searchsecurity.techtarget.com/definition/cryptanalysis

NEW QUESTION 12
A security engineer thinks the development team has been hard-coding sensitive environment variables in its code. Which of the following would BEST secure the company’s CI/CD pipeline?

  • A. Utilizing a trusted secrets manager
  • B. Performing DAST on a weekly basis
  • C. Introducing the use of container orchestration
  • D. Deploying instance tagging

Answer: A

Explanation:
Reference: https://about.gitlab.com/blog/2021/04/09/demystifying-ci-cd-variables/
CAS-004 dumps exhibit

NEW QUESTION 13
A technician is reviewing the logs and notices a large number of files were transferred to remote sites over the course of three months. This activity then stopped. The files were transferred via TLSprotected HTTP sessions from systems that do not send traffic to those sites.
The technician will define this threat as:

  • A. a decrypting RSA using obsolete and weakened encryption attack.
  • B. a zero-day attack.
  • C. an advanced persistent threat.
  • D. an on-path attack.

Answer: A

Explanation:
Reference: https://www.internetsociety.org/deploy360/tls/basics/

NEW QUESTION 14
A company’s SOC has received threat intelligence about an active campaign utilizing a specific vulnerability. The company would like to determine whether it is vulnerable to this active campaign.
Which of the following should the company use to make this determination?

  • A. Threat hunting
  • B. A system penetration test
  • C. Log analysis within the SIEM tool
  • D. The Cyber Kill Chain

Answer: B

NEW QUESTION 15
An organization recently experienced a ransomware attack. The security team leader is concerned about the attack reoccurring. However, no further security measures have been implemented.
Which of the following processes can be used to identify potential prevention recommendations?

  • A. Detection
  • B. Remediation
  • C. Preparation
  • D. Recovery

Answer: A

NEW QUESTION 16
......

P.S. Surepassexam now are offering 100% pass ensure CAS-004 dumps! All CAS-004 exam questions have been updated with correct answers: https://www.surepassexam.com/CAS-004-exam-dumps.html (128 New Questions)