[Jun-2026] CompTIA CAS-004 DUMPS WITH REAL EXAM QUESTIONS [Q198-Q223]

Share

[Jun-2026] CompTIA CAS-004 DUMPS WITH REAL EXAM QUESTIONS

2026 New ExamPrepAway CAS-004 PDF Recently Updated Questions


To prepare for the CASP+ exam, candidates should have a deep understanding of cybersecurity principles and best practices. They should also have experience in implementing secure solutions across a variety of enterprise environments. Candidates can prepare for the exam through self-study, online courses, or in-person training programs.

 

NEW QUESTION # 198
An administrator at a software development company would like to protect the integrity Of the company's applications with digital signatures. The developers report that the signing process keeps failing on all applications. The same key pair used for signing, however, is working properly on the website, is valid, and is issued by a trusted CA. Which of the following is MOST likely the cause of the signature failing?

  • A. Each application is missing a SAN or wildcard entry on the certificate.
  • B. The NTP server is set incorrectly for the developers.
  • C. The certificate is set for the wrong key usage.
  • D. The CA has included the certificate in its CRL_

Answer: C

Explanation:
Digital signatures require the use of a cryptographic key pair, which consists of a private key used to sign the application and a public key used to verify the signature. If the certificate used for signing the application is set for the wrong key usage, then the signature will fail. This can happen if the certificate is set for encrypting data instead of signing data, or if the certificate is set for the wrong algorithm, such as using an RSA key for an ECDSA signature.


NEW QUESTION # 199
A security architect is reviewing the following organizational specifications for a new application:
* Be sessionless and API-based
* Accept uploaded documents with Pll, so all storage must be ephemeral
* Be able to scale on-demand across multiple nodes
* Restrict all network access except for the TLS port
Which of the following ways should the architect recommend the application be deployed in order to meet security and organizational infrastructure requirements?

  • A. Utilizing the cloud container service
  • B. On server instances with autoscaling groups
  • C. Using scripted delivery
  • D. With a content delivery network

Answer: A

Explanation:
A cloud container service is the best way to meet the security and organizational infrastructure requirements described. Containers are sessionless, scalable, and can enforce ephemeral storage, which ensures that sensitive data like Personally Identifiable Information (PII) is only stored temporarily. Containers also restrict access to only necessary ports, such as TLS, and can easily scale across multiple nodes to handle varying workloads. CASP+ emphasizes the use of containers in modern, scalable, and secure application deployments, especially for API-based, sessionless applications that require flexible scaling and network security controls.
References:
* CASP+ CAS-004 Exam Objectives: Domain 3.0 - Enterprise Security Architecture (Containers and Cloud Services for Secure Application Deployment)
* CompTIA CASP+ Study Guide: Deploying Scalable and Secure Applications with Containers


NEW QUESTION # 200
A disaster recovery team learned of several mistakes that were made during the last disaster recovery parallel test. Computational resources ran out at 70% of restoration of critical services.
Which of the following should be modified to prevent the issue from reoccurring?

  • A. Recovery time objective
  • B. Recovery service level
  • C. Recovery point objective
  • D. Mission-essential functions

Answer: B

Explanation:
Reference: https://www.nakivo.com/blog/disaster-recovery-in-cloud-computing/ The recovery service level is a metric that defines the minimum level of service or performance that a system or process must provide after a disaster or disruption. The recovery service level can include parameters such as availability, capacity, throughput, latency, etc. The recovery service level should be modified to prevent the issue of running out of computational resources at 70% of restoration of critical services. The recovery service level should be aligned with the recovery point objective (RPO) and the recovery time objective (RTO), which are the maximum acceptable amount of data loss and downtime respectively. References:
https://www.techopedia.com/definition/29836/recovery-service-level
https://www.ibm.com/cloud/learn/recovery-point-objective
https://www.ibm.com/cloud/learn/recovery-time-objective


NEW QUESTION # 201
A web application server is running a legacy operating system with an unpatched RCE (Remote Code Execution) vulnerability. The server cannot be upgraded until the corresponding application code is updated. Which of the following compensating controls would prevent successful exploitation?

  • A. HIPS
  • B. UEBA
  • C. CASB
  • D. Segmentation

Answer: D

Explanation:
Segmentation isolates the vulnerable server into a separate network segment, reducing its exposure to potential attackers. By implementing firewalls or virtual LANs (VLANs), segmentation minimizes the risk of lateral movement and external exploitation, aligning with CASP+ objective
1.3, which emphasizes implementing appropriate compensating controls to address vulnerabilities.


NEW QUESTION # 202
A company just released a new video card. Due to limited supply and high demand, attackers are employing automated systems to purchase the device through the company's web store so they can resell it on the secondary market. The company's intended customers are frustrated. A security engineer suggests implementing aCAPTCHAsystem on the web store to help reduce the number of video cards purchased through automated systems. Which of the following now describes the level of risk?

  • A. Transferred
  • B. Residual
  • C. Inherent
  • D. Mitigated
  • E. Low

Answer: B

Explanation:
Comprehensive and Detailed in-Depth
Understanding the Risk Levels:
Inherent Risk:
Theoriginal riskbefore any controls or mitigation measures are applied.
In this scenario, it represents therisk of automated purchases without CAPTCHA.
Residual Risk:
Theremaining riskaftermitigation strategieshave been applied.
After implementing CAPTCHA, some risk remains asCAPTCHA systems can be bypassedorhuman-operated botsmay still make purchases.
Mitigated Risk:
A risk that has beenreduced or managedeffectively.
While CAPTCHAmitigatesthe issue, it does noteliminateit.
Low Risk:
A risk that is consideredminordue to effective mitigation or low impact.
CAPTCHA reduces risk but does not guarantee it is low.
Transferred Risk:
A risk that has beenshifted to another entity, such asoutsourcing or insurance.
Implementing CAPTCHA does nottransfer riskbut ratherreduces it directly.
Why the Correct Answer is D (Residual):
Implementing CAPTCHAreduces the number of automated purchases, but therisk is not entirely eliminated.
There is always aresidual riskbecause:
Advanced botsmay bypass CAPTCHA systems.
Human-assisted purchasesmight still occur, as attackers might hire people to complete CAPTCHAs.
Therefore, the risk after implementing the CAPTCHA system isresidual, assome potential for automated purchases remains.
Why the Other Options Are Incorrect:
A . Inherent:
Inherent risk existsbeforeany mitigating actions, like CAPTCHA implementation.
Since the CAPTCHA is already suggested, we are addressing theresidual risk.
B . Low:
While CAPTCHA reduces the risk, itdoes not eliminate it completelyor make it negligible.
Attackers can stillbypass CAPTCHAusing more sophisticated methods.
C . Mitigated:
The CAPTCHA reduces risk butdoes not fully mitigate it.
The termmitigatedimplies a more comprehensive reduction than what CAPTCHA alone can provide.
E . Transferred:
There isno transfer of riskto another party or system.
CAPTCHA directlymitigatesrisk rather than shifting responsibility.
Real-World Scenario:
Whenpopular productsare released (like new GPUs), attackers usebotsto make bulk purchases.
Retailers implementCAPTCHA systemsto prevent automated orders.
However,bot developerscontinuously innovate tobypass CAPTCHA, leaving some level ofresidual risk.
Extract from CompTIA SecurityX CAS-005 Study Guide:
TheCompTIA SecurityX CAS-005 Official Study Guidedefinesresidual riskas therisk that remains after controls are implemented. Implementing aCAPTCHAsystem reduces thelikelihoodof automated purchases butdoes not fully eliminate the threat, thus leaving aresidual risk.


NEW QUESTION # 203
Which of the following terms refers to the delivery of encryption keys to a CASB or a third-party entity?

  • A. Key sharing
  • B. Key distribution
  • C. Key recovery
  • D. Key escrow

Answer: D

Explanation:
Explanation
Key escrow is a process that involves storing encryption keys with a trusted third party, such as a CASB (Cloud Access Security Broker) or a government agency. Key escrow can enable authorized access to encrypted data in case of emergencies, legal issues, or data recovery. However, key escrow also introduces some risks and challenges, such as trust, security, and privacy. References:
https://www.techopedia.com/definition/1772/key-escrow
https://searchsecurity.techtarget.com/definition/key-escrow


NEW QUESTION # 204
A company is concerned about disgruntled employees transferring its intellectual property data through covert channels.
Which of the following tools would allow employees to write data into ICMP echo response packets?

  • A. Burp Suite
  • B. Thor
  • C. Loki
  • D. Jack the Ripper

Answer: C


NEW QUESTION # 205
A security analyst is concerned that a malicious piece of code was downloaded on a Linux system. After some research, the analyst determines that the suspected piece of code is performing a lot of input/output (I/O) on the disk drive.

Based on the output above, from which of the following process IDs can the analyst begin an investigation?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B


NEW QUESTION # 206
The Chief information Officer (CIO) wants to implement enterprise mobility throughout the organization. The goal is to allow employees access to company resources. However the CIO wants the ability to enforce configuration settings, manage data, and manage both company- owned and personal devices.
Which of the following should the CIO implement to achieve this goal?

  • A. BYOO
  • B. CYOD
  • C. MDM
  • D. COPE

Answer: C

Explanation:
Enterprise Mobility Management (EMM) describes a suite of policies and technology tools designed to enable centralized management and control of mobile devices in a corporate setting.
Whether corporate or personally owned, EMM governs the ways in which users interact with devices and how users, devices, and apps integrate with the organization's larger network so as to enable high-levels of mobility while simultaneously ensuring information security. A subset of EMM, Mobile Device Management (MDM) focuses on the control of mobile devices to ensure compliance with an organization's security requirements.


NEW QUESTION # 207
Due to adverse events, a medium-sized corporation suffered a major operational disruption that caused its servers to crash and experience a major power outage. Which of the following should be created to prevent this type of issue in the future?

  • A. RTO
  • B. BIA
  • C. BCP
  • D. SLA
  • E. BCM

Answer: C

Explanation:
Explanation
A Business Continuity Plan (BCP) is a set of policies and procedures that outline how an organization should respond to and recover from disruptions [1]. It is designed to ensure that critical operations and services can be quickly restored and maintained, and should include steps to identify risks, develop plans to mitigate those risks, and detail the procedures to be followed in the event of a disruption. Resources:
CompTIA Advanced Security Practitioner (CASP+) Study Guide, Chapter 4: "Business Continuity Planning," Wiley,
2018. https://www.wiley.com/en-us/CompTIA+Advanced+Security+Practitioner+CASP%2B+Study+Guide%2C


NEW QUESTION # 208
Prior to a risk assessment inspection, the Chief Information Officer tasked the systems administrator with analyzing and reporting any configuration issues on the information systems, and then verifying existing security settings. Which of the following would be BEST to use?

  • A. CVSS
  • B. SCAP
  • C. XCCDF
  • D. CMDB

Answer: C


NEW QUESTION # 209
A security analyst is concerned that a malicious piece of code was downloaded on a Linux system. After some research, the analyst determines that the suspected piece of code is performing a lot of input/output (I/O) on the disk drive.

Based on the output above, from which of the following process IDs can the analyst begin an investigation?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

Explanation:
The process ID 87 can be the starting point for an investigation of a possible buffer overflow attack, as it shows a high percentage of CPU utilization (99.7%) and a suspicious command name (graphic.linux_randomization.prg). A buffer overflow attack is a type of attack that exploits a vulnerability in an application or system that allows an attacker to write data beyond the allocated buffer size, potentially overwriting memory segments and executing malicious code. A high CPU utilization could indicate that the process is performing intensive or abnormal operations, such as a buffer overflow attack. A suspicious command name could indicate that the process is trying to disguise itself or evade detection, such as by mimicking a legitimate program or using random characters. The other process IDs do not show signs of a buffer overflow attack, as they have low CPU utilization and normal command names. Verified References:
https://www.comptia.org/blog/what-is-buffer-overflowhttps://partners.comptia.org/docs/default-source/resources


NEW QUESTION # 210
A network administrator receives a ticket regarding an error from a remote worker who is trying to reboot a laptop. The laptop has not yet loaded the operating system, and the user is unable to continue the boot process. The administrator is able to provide the user with a recovery PIN, and the user is able to reboot the system and access the device as needed. Which of the following is the MOST likely cause of the error?

  • A. Failure of the Kerberos time drift sync
  • B. Duration of the BitLocker lockout period
  • C. Failure of TPM authentication
  • D. Lockout of privileged access account

Answer: C

Explanation:
The most likely cause of the error is the failure of TPM authentication. TPM stands for Trusted Platform Module, which is a hardware component that stores encryption keys and other security information. TPM can be used by BitLocker to protect the encryption keys and verify the integrity of the boot process. If TPM fails to authenticate the laptop, BitLocker will enter recovery mode and ask for a recovery PIN, which is a 48-digit numerical password that can be used to unlock the system. The administrator should check the TPM status and configuration and make sure it is working properly. Verified Reference:
https://support.microsoft.com/en-us/windows/finding-your-bitlocker-recovery-key-in-windows-6b71ad27-0b89-ea08-f143-056f5ab347d6
https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/bitlocker-recovery-guide-plan
https://docs.sophos.com/esg/sgn/8-1/user/win/en-us/esg/SafeGuard-Enterprise/tasks/BitLockerRecoveryKey.html


NEW QUESTION # 211
A company is repeatedly being breached by hackers who valid credentials. The company's Chief information Security Officer (CISO) has installed multiple controls for authenticating users, including biometric and token-based factors. Each successive control has increased overhead and complexity but has failed to stop further breaches. An external consultant is evaluating the process currently in place to support the authentication controls. Which of the following recommendation would MOST likely reduce the risk of unauthorized access?

  • A. Implement strict three-factor authentication.
  • B. Strengthen identify-proofing procedures
  • C. Implement least privilege policies
  • D. Switch to one-time or all user authorizations.

Answer: A


NEW QUESTION # 212
Which of the following is the MOST important cloud-specific risk from the CSP's viewpoint?

  • A. Resource exhaustion
  • B. Isolation control failure
  • C. Management plane breach
  • D. Insecure data deletion

Answer: D


NEW QUESTION # 213
A company recently migrated its critical web application to a cloud provider's environment. As part of the company's risk management program, the company intends to conduct an external penetration test. According to the scope of work and the rules of engagement, the penetration tester will validate the web application's security and check for opportunities to expose sensitive company information in the newly migrated cloud environment. Which of the following should be the first consideration prior to engaging in the test?

  • A. Ensure the latest patches and signatures are deployed on the web server.
  • B. Obtain agreement between the company and the cloud provider to conduct penetration testing.
  • C. Prepare a redundant server to ensure the critical web application's availability during the test.
  • D. Create an NDA between the external penetration tester and the company.

Answer: B

Explanation:
Before conducting a penetration test in a cloud environment, it is critical to first obtain permission from the cloud service provider. Cloud providers often have strict rules about penetration testing to avoid unintended service disruptions or violations of service agreements. Without this agreement, the company could face legal or operational consequences. This aligns with CASP+ best practices, which emphasize the importance of securing approval and understanding shared responsibility models in cloud environments before engaging in security testing.
References:
* CASP+ CAS-004 Exam Objectives: Domain 1.0 - Risk Management (Penetration Testing in Cloud Environments)
* CompTIA CASP+ Study Guide: Cloud Security and Legal Considerations for Penetration Testing


NEW QUESTION # 214
A network administrator receives a ticket regarding an error from a remote worker who is trying to reboot a laptop. The laptop has not yet loaded the operating system, and the user is unable to continue the boot process. The administrator is able to provide the user with a recovery PIN, and the user is able to reboot the system and access the device as needed. Which of the following is the MOST likely cause of the error?

  • A. Failure of the Kerberos time drift sync
  • B. Duration of the BitLocker lockout period
  • C. Failure of TPM authentication
  • D. Lockout of privileged access account

Answer: C

Explanation:
The most likely cause of the error is the failure of TPM authentication. TPM stands for Trusted Platform Module, which is a hardware component that stores encryption keys and other security information. TPM can be used by BitLocker to protect the encryption keys and verify the integrity of the boot process. If TPM fails to authenticate the laptop, BitLocker will enter recovery mode and ask for a recovery PIN, which is a 48-digit numerical password that can be used to unlock the system. The administrator should check the TPM status and configuration and make sure it is working properly.


NEW QUESTION # 215
A security architect Is analyzing an old application that is not covered for maintenance anymore because the software company is no longer in business. Which of the following techniques should have been Implemented to prevent these types of risks?

  • A. Supply chain visibility
  • B. Code reviews
  • C. Software audits
  • D. Source code escrows

Answer: D

Explanation:
Explanation
A source code escrow is a legal agreement that involves a third party holding the source code of a software application on behalf of the software vendor and the software licensee. The source code escrow ensures that the licensee can access the source code in case the vendor goes out of business, fails to provide maintenance or support, or breaches the contract terms.
A source code escrow would have prevented the risk of having an old application that is not covered for maintenance anymore because the software company is no longer in business, because it would:
Allow the licensee to obtain the source code and continue to update, fix, or modify the application according to their needs.
Protect the vendor's intellectual property rights and prevent unauthorized disclosure or use of the source code.
Provide a legal framework and a trusted mediator for resolving any disputes or issues between the vendor and the licensee.


NEW QUESTION # 216
A company wants to improve Its active protection capabilities against unknown and zero-day malware. Which of the following Is the MOST secure solution?

  • A. Application allow list
  • B. Sandbox detonation
  • C. Endpoint log collection
  • D. NIDS
  • E. HIDS

Answer: B

Explanation:
Sandbox security testing proactively detects malware by running suspicious code in a safe and isolated environment, and monitoring the behavior and outputs of the code. This is known as
"detonation". The major advantage of sandbox-based security testing is that it can reliably detect unknown threats


NEW QUESTION # 217
An architect is designing security scheme for an organization that is concerned about APTs. Any proposed architecture must meet the following requirements:
- Services must be able to be reconstituted quickly from a known-good state.
- Network services must be designed to ensure multiple diverse layers of redundancy.
- Defensive and responsive actions must be automated to reduce human operator demands.
Which of the following designs must be considered to ensure the architect meets these requirements? (Choose three.)

  • A. Implementation and configuration of a SOAR
  • B. Hardened and verified container usage
  • C. Establishment of warm and hot sites for continuity of operations
  • D. Deployment of IPS services that can identify and block malicious traffic
  • E. Geographic distribution of critical data and services
  • F. Emulated hardware architecture usage
  • G. Heterogeneous architecture
  • H. Increased efficiency by embracing advanced caching capabilities

Answer: A,B,E

Explanation:
B). Geographic distribution of critical data and services will ensure that multiple sites are available to restore data and services in the event of an APT attack. This will also reduce the impact of DDoS attacks by ensuring that traffic is spread across multiple sites.
C). Hardened and verified container usage can help to isolate services from one another and protect them from APT attacks. Containerization can provide a secure and scalable platform for deploying services, which can be reconstituted quickly from a known-good state.
H). Implementation and configuration of a SOAR platform will automate the process of responding to and mitigating APT attacks. The SOAR platform will allow the organization to create a set of automated actions that can be executed in response to security events, reducing the human operator demands.


NEW QUESTION # 218
A security analyst identified a vulnerable and deprecated runtime engine that is supporting a public-facing banking application. The developers anticipate the transition to modern development environments will take at least a month. Which of the following controls would best mitigate the risk without interrupting the service during the transition?

  • A. Shutting down the systems until the code is ready
  • B. Selectively blocking traffic on the affected port
  • C. Configuring IPS and WAF with signatures
  • D. Uninstalling the impacted runtime engine

Answer: C

Explanation:
Given the vulnerability in the deprecated runtime engine, configuring an IPS (Intrusion Prevention System) and WAF (Web Application Firewall) with appropriate signatures is the best temporary control. This allows the organization to monitor and block potential attacks targeting known vulnerabilities in the runtime engine while the developers work on the transition. Shutting down the systems or uninstalling the runtime engine would cause service interruptions, and blocking traffic might disrupt legitimate users. IPS and WAF provide an active layer of defense without interrupting service. CASP+ emphasizes the use of layered security, including IPS and WAF, to mitigate risks in public-facing applications.
References:
* CASP+ CAS-004 Exam Objectives: Domain 3.0 - Enterprise Security Architecture (Web Application Firewalls, Intrusion Prevention Systems)
* CompTIA CASP+ Study Guide: Mitigating Application Vulnerabilities with WAFs and IPS


NEW QUESTION # 219
When implementing serverless computing an organization must still account for:

  • A. hardware compatibility
  • B. the underlying computing network infrastructure
  • C. the security of its data
  • D. patching the service

Answer: C

Explanation:
While serverless computing abstracts the infrastructure layer from developers, organizations must still ensure the security of their data in the serverless environment. This includes protecting the data from unauthorized access and ensuring data privacy and integrity. Serverless architectures can be complex, and understanding the security model and shared responsibility is essential for safeguarding applications and services.


NEW QUESTION # 220
SIMULATION
You are about to enter the virtual environment.
Once you have completed the item in the virtual environment, you will NOT be allowed to return to this item.
Click Next to continue.

Question and Instructions
DO NOT perform the following actions within the virtual environment. Making any of these changes will cause the virtual environment to fail and prevent proper scoring.
1. Disabling ssh
2. Disabling systemd
3. Altering the network adapter 172.162.0.0
4. Changing the password in the lab admin account
Once you have completed the item in the virtual environment. you will NOT be allowed to return to this item.
TEST QUESTION
This system was recently patched following the exploitation of a vulnerability by an attacker to enable data exfiltration.
Despite the vulnerability being patched, it is likely that a malicious TCP service is still running and the adversary has achieved persistence by creating a systemd service.
Examples of commands to use:
kill, killall
lsof
man, --help (use for assistance)
netstat (useful flags: a, n, g, u)
ps (useful flag: a)
systemctl (to control systemd)
Please note: the list of commands shown above is not exhaustive. All native commands are available.
INSTRUSTIONS
Using the following credentials:
Username: labXXXadmin
Password: XXXyyYzz!
Investigate to identify indicators of compromise and then remediate them. You will need to make at least two changes:
1. End the compromised process that is using a malicious TCP service.
2. Remove the malicious persistence agent by disabling the service's ability to start on boot.

Answer:

Explanation:
Use sudo before any command the password is the same password provided, everything in <> is not part of the command is variable. Sudo will show you every detail you need. First command
$sudo netstat -nltp, this will show you ip, port, pid, name of task.
For added value you can also run $sudo lsof -i :<port>. Now you need to find the service so you use $sudo systemctl --type=service | grep <name of task>, this will give you <something>.service my was <something>-resolve.service forgot the full name.
Suggest you do a $sudo systemctl status <full name service> to compare. After all that lets kill it all, First kill the pid $sudo kill -9 <pid>. Then lets complete the second part $sudo systemctl stop
<full name service>, follow by $sudo systemctl disable <full name service>.
Now for the cream on the top you verify that is gone $sudo netstat -nltp and $sudo systemctl status <full name service>.


NEW QUESTION # 221
A company has a website with a huge database. The company wants to ensure that a DR site could be brought online quickly in the event of a failover, and end users would miss no more than
30 minutes of data. Which of the following should the company do to meet these objectives?

  • A. Store the nightly full backups at the DR site.
  • B. Implement real-time replication for the DR site.
  • C. Increase the network bandwidth to the DR site.
  • D. Build a content caching system at the DR site.

Answer: B

Explanation:
To meet the objective of ensuring minimal data loss (no more than 30 minutes of data) in case of a failover, real-time replication is the best solution. This technique involves continuously replicating data from the primary site to the disaster recovery (DR) site, minimizing data loss to the smallest possible timeframe (i.e., near real-time). Other options, such as content caching or nightly backups, do not address the requirement for minimal data loss effectively. Increasing bandwidth to the DR site may help with the recovery process but will not necessarily reduce the amount of lost data.


NEW QUESTION # 222
A company is outsourcing to an MSSP that performs managed detection and response services. The MSSP requires a server to be placed inside the network as a log aggregate and allows remote access to MSSP analyst.
Critical devices send logs to the log aggregator, where data is stored for 12 months locally before being archived to a multitenant cloud. The data is then sent from the log aggregate to a public IP address in the MSSP datacenter for analysis.
A security engineer is concerned about the security of the solution and notes the following.
* The critical devise send cleartext logs to the aggregator.
* The log aggregator utilize full disk encryption.
* The log aggregator sends to the analysis server via port 80.
* MSSP analysis utilize an SSL VPN with MFA to access the log aggregator remotely.
* The data is compressed and encrypted prior to being achieved in the cloud.
Which of the following should be the engineer's GREATEST concern?

  • A. Hardware vulnerabilities introduced by the log aggregate server
  • B. Encryption of data in transit
  • C. Multinancy and data remnants in the cloud
  • D. Network bridging from a remote access VPN

Answer: B

Explanation:
Encryption of data in transit should be the engineer's greatest concern regarding the security of the solution.
Data in transit refers to data that is being transferred over a network or between devices. If data in transit is not encrypted, it can be intercepted, modified, or stolen by attackers who can exploit vulnerabilities in the network protocols or devices. The solution in the question sends logs from the critical devices to the aggregator in cleartext and from the aggregator to the analysis server via port 80, which are both insecure methods that expose the data to potential attacks. Verified References:
https://www.comptia.org/training/books/casp-cas-004-study-guide ,https://us-cert.cisa.gov/ncas/tips/ST04-019


NEW QUESTION # 223
......

Latest CAS-004 Pass Guaranteed Exam Dumps Certification Sample Questions: https://www.examprepaway.com/CompTIA/braindumps.CAS-004.ete.file.html

CAS-004 Exam with Guarantee Updated 620 Questions: https://drive.google.com/open?id=1q42WTNXKavJNieq6zlYGOcxhBZthxGRL