CompTIA CAS-004 Dumps - 100% Cover Real Exam Questions (Updated 130 Questions)
Real CAS-004 dumps - Real CompTIA dumps PDF
NEW QUESTION 12
A Chief information Security Officer (CISO) has launched to create a rebuts BCP/DR plan for the entire company. As part of the initiative , the security team must gather data supporting s operational importance for the applications used by the business and determine the order in which the application must be back online. Which of the following be the FIRST step taken by the team?
- A. Perform a review of all policies an procedures related to BGP a and DR and created an educated educational module that can be assigned to at employees to provide training on BCP/DR events.
- B. Implement replication of all servers and application data to back up detacenters that are geographically from the central datacenter and release an upload BPA to all clients.
- C. Have each business unit conduct a BIA and categories the application according to the cumulative data gathered.
- D. Create an SLA for each application that states when the application will come back online and distribute this information to the business units.
Answer: C
NEW QUESTION 13
A security architect works for a manufacturing organization that has many different branch offices. The architect is looking for a way to reduce traffic and ensure the branch offices receive the latest copy of revoked certificates issued by the CA at the organization's headquarters location. The solution must also have the lowest power requirement on the CA.
Which of the following is the BEST solution?
- A. Send the new CRLs by using GPO.
- B. Use Delta CRLs at the branches.
- C. Configure clients to use OCSP.
- D. Deploy an RA on each branch office.
Answer: C
NEW QUESTION 14
A company that uses AD is migrating services from LDAP to secure LDAP. During the pilot phase, services are not connecting properly to secure LDAP. Block is an except of output from the troubleshooting session:
Which of the following BEST explains why secure LDAP is not working? (Select TWO.)
- A. The company is using the wrong port. It should be using port 389 for secure LDAP.
- B. Secure LDAP should be running on UDP rather than TCP.
- C. The clients may not trust idapt by default.
- D. Secure LDAP does not support wildcard certificates.
- E. Danvills.com is under a DDoS-inator attack and cannot respond to OCSP requests.
- F. The secure LDAP service is not started, so no connections can be made.
- G. The clients may not trust Chicago by default.
Answer: A,F
NEW QUESTION 15
A cybersecurity analyst receives a ticket that indicates a potential incident is occurring. There has been a large in log files generated by a generated by a website containing a ''Contact US'' form. The analyst must determine if the increase in website traffic is due to a recent marketing campaign of if this is a potential incident. Which of the following would BEST assist the analyst?
- A. Running the website log files through a log reduction and analysis tool
- B. Checking for new rules from the inbound network IPS vendor
- C. Deploy a WAF in front of the public website
- D. Ensuring proper input validation is configured on the ''Contact US'' form
Answer: A
NEW QUESTION 16
A security analyst is trying to identify the source of a recent data loss incident. The analyst has reviewed all the for the time surrounding the identified all the assets on the network at the time of the data loss. The analyst suspects the key to finding the source was obfuscated in an application. Which of the following tools should the analyst use NEXT?
- A. Log reduction and analysis tool
- B. Network enurrerator
- C. Software Decomplier
- D. Static code analysis
Answer: D
NEW QUESTION 17
Which of the following allows computation and analysis of data within a ciphertext without knowledge of the plaintext?
- A. Lattice-based cryptography
- B. Quantum computing
- C. Asymmetric cryptography
- D. Homomorphic encryption
Answer: C
NEW QUESTION 18
A Chief Information Officer is considering migrating all company data to the cloud to save money on expensive SAN storage.
Which of the following is a security concern that will MOST likely need to be addressed during migration?
- A. Data dispersion
- B. Data loss
- C. Latency
- D. Data exposure
Answer: C
NEW QUESTION 19
A security architect is implementing a web application that uses a database back end. Prior to the production, the architect is concerned about the possibility of XSS attacks and wants to identify security controls that could be put in place to prevent these attacks.
Which of the following sources could the architect consult to address this security concern?
- A. OWASP
- B. IEEE
- C. SDLC
- D. OVAL
Answer: D
NEW QUESTION 20
A new web server must comply with new secure-by-design principles and PCI DSS. This includes mitigating the risk of an on-path attack. A security analyst is reviewing the following web server configuration:
Which of the following ciphers should the security analyst remove to support the business requirements?
- A. TLS_AES_128_GCM_SHA256
- B. TLS_CHACHA20_POLY1305_SHA256
- C. TLS_DHE_DSS_WITH_RC4_128_SHA
- D. TLS_AES_128_CCM_8_SHA256
Answer: B
NEW QUESTION 21
A company created an external application for its customers. A security researcher now reports that the application has a serious LDAP injection vulnerability that could be leveraged to bypass authentication and authorization.
Which of the following actions would BEST resolve the issue? (Choose two.)
- A. Deploy a WAF.
- B. Use containers.
- C. Deploy an IDS.
- D. Deploy a SIEM.
- E. Patch the OS
- F. Conduct input sanitization.
- G. Deploy a reverse proxy
Answer: D,E
NEW QUESTION 22
During a system penetration test, a security engineer successfully gained access to a shell on a Linux host as a standard user and wants to elevate the privilege levels.
Which of the following is a valid Linux post-exploitation method to use to accomplish this goal?
- A. Perform ASIC password cracking on the host.
- B. Use the UNION operator to extract the database schema.
- C. Spawn a shell using sudo and an escape string such as sudo vim -c '!sh'.
- D. Initiate unquoted service path exploits.
- E. Read the /etc/passwd file to extract the usernames.
Answer: E
NEW QUESTION 23
A satellite communications ISP frequently experiences outages and degraded modes of operation over one of its legacy satellite links due to the use of deprecated hardware and software. Three days per week, on average, a contracted company must follow a checklist of 16 different high-latency commands that must be run in serial to restore nominal performance. The ISP wants this process to be automated.
Which of the following techniques would be BEST suited for this requirement?
- A. Provide the contractors with direct access to satellite telemetry data.
- B. Deploy SOAR utilities and runbooks.
- C. Replace the associated hardware.
- D. Reduce link latency on the affected ground and satellite segments.
Answer: B
NEW QUESTION 24
A cybersecurity engineer analyst a system for vulnerabilities. The tool created an OVAL. Results document as output. Which of the following would enable the engineer to interpret the results in a human readable form? (Select TWO.)
- A. OOXML editor
- B. XML style sheet
- C. Text editor
- D. Event Viewer
- E. SCAP tool
- F. Debugging utility
Answer: C,E
NEW QUESTION 25
Which of the following are risks associated with vendor lock-in? (Choose two.)
- A. The client can seamlessly move data.
- B. The vendor can change product offerings.
- C. The client can leverage a multicloud approach.
- D. The client receives a sufficient level of service.
- E. The client experiences increased interoperability.
- F. The client experiences decreased quality of service.
Answer: B,F
NEW QUESTION 26
An organization is considering a BYOD standard to support remote working. The first iteration of the solution will utilize only approved collaboration applications and the ability to move corporate data between those applications. The security team has concerns about the following:
Unstructured data being exfiltrated after an employee leaves the organization Data being exfiltrated as a result of compromised credentials Sensitive information in emails being exfiltrated Which of the following solutions should the security team implement to mitigate the risk of data loss?
- A. Conditional access, DoH, and full disk encryption
- B. Mobile device management, remote wipe, and data loss detection
- C. Mobile application management, MFA, and DRM
- D. Certificates, DLP, and geofencing
Answer: B
NEW QUESTION 27
While investigating a security event, an analyst finds evidence that a user opened an email attachment from an unknown source. Shortly after the user opened the attachment, a group of servers experienced a large amount of network and resource activity. Upon investigating the servers, the analyst discovers the servers were encrypted by ransomware that is demanding payment within 48 hours or all data will be destroyed. The company has no response plans for ransomware.
Which of the following is the NEXT step the analyst should take after reporting the incident to the management team?
- A. Notify law enforcement.
- B. Isolate the servers to prevent the spread.
- C. Request that the affected servers be restored immediately.
- D. Pay the ransom within 48 hours.
Answer: A
NEW QUESTION 28
Which of the following controls primarily detects abuse of privilege but does not prevent it?
- A. Least privilege
- B. Separation of duties
- C. Job rotation
- D. Off-boarding
Answer: D
NEW QUESTION 29
A company's claims processed department has a mobile workforce that receives a large number of email submissions from personal email addresses. An employees recently received an email that approved to be claim form, but it installed malicious software on the employee's laptop when was opened.
- A. Required all laptops to connect to the VPN before accessing email.
- B. Impalement application whitelisting and add only the email client to the whitelist for laptop in the claims processing department.
- C. Implement cloud-based content filtering with sandboxing capabilities.
- D. Install a mail gateway to scan incoming messages and strip attachments before they reach the mailbox.
Answer: C
NEW QUESTION 30
A company wants to protect its intellectual property from theft. The company has already applied ACLs and DACs.
Which of the following should the company use to prevent data theft?
- A. Watermarking
- B. Access logging
- C. NDA
- D. DRM
Answer: B
NEW QUESTION 31
A high-severity vulnerability was found on a web application and introduced to the enterprise. The vulnerability could allow an unauthorized user to utilize an open-source library to view privileged user information. The enterprise is unwilling to accept the risk, but the developers cannot fix the issue right away.
Which of the following should be implemented to reduce the risk to an acceptable level until the issue can be fixed?
- A. Deploy a VPN, configure an official open-source library repository, and perform a full application review for vulnerabilities.
- B. Change privileged usernames, review the OS logs, and deploy hardware tokens.
- C. Scan the code with a static code analyzer, change privileged user passwords, and provide security training.
- D. Implement MFA, review the application logs, and deploy a WAF.
Answer: A
NEW QUESTION 32
A technician is reviewing the logs and notices a large number of files were transferred to remote sites over the course of three months. This activity then stopped. The files were transferred via TLS-protected HTTP sessions from systems that do not send traffic to those sites.
The technician will define this threat as:
- A. a decrypting RSA using obsolete and weakened encryption attack.
- B. an advanced persistent threat.
- C. an on-path attack.
- D. a zero-day attack.
Answer: A
NEW QUESTION 33
......
Realistic Test4Engine CAS-004 Dumps PDF - 100% Passing Guarantee: https://www.test4engine.com/CAS-004_exam-latest-braindumps.html
Free CompTIA CAS-004 Exam Questions and Answer: https://drive.google.com/open?id=1NHs05JvSjdTdX4WyMksxXRO_0G5VxbZ0