[Jun 13, 2026] Pass CompTIA CAS-004 Exam Info and Free Practice Test
CAS-004 Exam Dumps PDF Updated Dump from Exam4Free Guaranteed Success
NEW QUESTION # 137
A Chief Information Officer is considering migrating all company data to the cloud to save money on expensive SAN storage.
Which of the following is a security concern that will MOST likely need to be addressed during migration?
- A. Data loss
- B. Data exposure
- C. Data dispersion
- D. Latency
Answer: B
Explanation:
Data exposure refers to the risk that sensitive data may be accessed by unauthorized parties.
This can occur when data is stored in the cloud, as the data may be more vulnerable to being accessed by hackers or other malicious actors. To address this concern, the Chief Information Officer should ensure that the cloud provider has robust security measures in place to protect the data, such as encryption, access controls, and monitoring.
NEW QUESTION # 138
An organization is struggling to differentiate threats from normal traffic and access to systems. A security engineer has been asked to recommend a system that will aggregate data and provide metrics that will assist in identifying malicious actors or other anomalous activity throughout the environment. Which of the following solutions should the engineer recommend?
- A. SIEM
- B. Web application firewall
- C. File integrity monitor
- D. IPS
- E. UTM
Answer: A
NEW QUESTION # 139
A security researcher detonated some malware in a lab environment and identified the following commands running from the EDR tool:
With which of the following MITRE ATT&CK TTPs is the command associated? (Select TWO).
- A. Indirect command execution
- B. Network denial of service
- C. OS credential dumping
- D. System information discovery
- E. Inhibit system recovery
- F. External remote services
Answer: C,D
Explanation:
OS credential dumping is the process of obtaining account login and password information, normally in the form of a hash or a clear text password, from the operating system and software. System information discovery is the process of gathering information about the system, such as hostname, IP address, OS version, running processes, etc. Both of these techniques are commonly used by adversaries to gain access to sensitive data and resources on the target system. The command shown in the image is using Mimikatz, a tool that can dump credentials from memory, and also querying the system information using WMIC. Verified Reference:
https://attack.mitre.org/techniques/T1003/
https://attack.mitre.org/techniques/T1082/
https://github.com/gentilkiwi/mimikatz
https://docs.microsoft.com/en-us/windows/win32/wmisdk/wmic
NEW QUESTION # 140
A company plans to build an entirely remote workforce that utilizes a cloud-based infrastructure.
The Chief Information Security Officer asks the security engineer to design connectivity to meet the following requirements:
- Only users with corporate-owned devices can directly access servers
hosted by the cloud provider.
- The company can control what SaaS applications each individual user
can access.
- User browser activity can be monitored.
Which of the following solutions would BEST meet these requirements?
- A. SSL tunnel, DLP, and host-based firewall
- B. VPN, CASB, and secure web gateway
- C. IAM gateway, MDM, and reverse proxy
- D. API gateway, UEM, and forward proxy
Answer: B
Explanation:
A VPN would ensure that only corporate-owned devices can directly access the cloud-based infrastructure.
A Cloud Access Security Broker (CASB) can control the access of individual users to SaaS applications, fulfilling the second requirement.
A secure web gateway can monitor user browser activity, satisfying the final requirement. The secure web gateway acts as a security layer between the users and the internet, allowing for the monitoring and controlling of web traffic and ensuring that only authorized web resources are accessible.
NEW QUESTION # 141
An analyst reviews the following output collected during the execution of a web application security assessment:
Which of the following attacks would be most likely to succeed, given the output?
- A. NULL and unauthenticated cipher downgrade attack
- B. Availability attack from manipulation of associated authentication data
- C. On-path forced renegotiation to insecure ciphers
- D. Padding oracle attack
Answer: D
Explanation:
Based on the output in the image, which shows weak cipher suites and vulnerabilities related to encryption padding, the padding oracle attack is the most likely. This type of attack exploits the way padding errors are handled during decryption, potentially allowing an attacker to decrypt sensitive information. The weak cipher suites and lack of forward secrecy further increase the likelihood of such an attack succeeding. CASP+ highlights padding oracle attacks as critical vulnerabilities, particularly in environments where weak encryption protocols are used.
References:
CASP+ CAS-004 Exam Objectives: Domain 2.0 - Enterprise Security Operations (Encryption and Padding Oracle Attacks) CompTIA CASP+ Study Guide: Cryptographic Attacks and Cipher Vulnerabilities
NEW QUESTION # 142
A company wants to quantify and communicate the effectiveness of its security controls but must establish measures. Which of the following is MOST likely to be included in an effective assessment roadmap for these controls?
- A. Create a change management process.
- B. Establish key performance indicators.
- C. Create an integrated master schedule.
- D. Develop a communication plan.
- E. Perform a security control assessment.
Answer: B
Explanation:
Key Performance Indicators are a formal mechanism designed to measure the effectiveness of a cybersecurity program by defining the crucial goals and desired outcomes of the program.
NEW QUESTION # 143
An organization wants to implement an access control system based on its data classification policy that includes the following data types:
Confidential
Restricted
Internal
Public
The access control system should support SSO federation to map users into groups. Each group should only access systems that process and store data at the classification assigned to the group. Which of the following should the organization implement to enforce its requirements with minimal impact to systems and resources?
- A. Role-based access control that maps data types to internal roles, which are defined in the human resources department's source of truth system.
- B. A rule-based access control strategy enforced by the SSO system with rules managed by the internal LDAP and applied on a per-system basis.
- C. Network microsegmentation based on data types, and a network access control system enforcing mandatory access control based on the user principal.
- D. A tagging strategy in which all resources are assigned a tag based on the data classification type, and a system that enforces attribute-based access control.
Answer: D
Explanation:
Attribute-Based Access Control (ABAC) with a tagging strategy allows flexible and granular access control based on resource classification and user attributes. This minimizes system impact and ensures compliance with data classification policies. This aligns with CASP+ objective 3.4, focusing on advanced access control mechanisms.
NEW QUESTION # 144
A recent data breach revealed that a company has a number of files containing customer data across its storage environment. These files are individualized for each employee and are used in tracking various customer orders, inquiries, and issues. The files are not encrypted and can be accessed by anyone. The senior management team would like to address these issues without interrupting existing processes.
Which of the following should a security architect recommend?
- A. A CRM application to consolidate the data and provision access based on the process and need
- B. An ERP program to identify which processes need to be tracked
- C. A CMDB to report on systems that are not configured to security baselines
- D. A DLP program to identify which files have customer data and delete them
Answer: A
Explanation:
A CRM application is a type of software that helps organizations manage customer relationships and interactions, including storing and organizing customer data. By consolidating the customer data files into a CRM application and implementing proper access controls, the company can ensure that the data is protected and that only authorized employees have access to it.
The security architect should recommend that the CRM application be configured to provision access based on the process and need, so that employees only have access to the data that they need to perform their duties. This can help reduce the risk of unauthorized access to the data and ensure that the data is being used appropriately.
NEW QUESTION # 145
Which of the following BEST sets expectation between the security team and business units within an organization?
- A. Risk assessment
- B. Services level agreement
- C. Business impact analysis
- D. Memorandum of understanding
- E. Business partnership agreement
Answer: B
Explanation:
A service level agreement (SLA) is the best option to set expectations between the security team and business units within an organization. An SLA is a document that defines the scope, quality, roles, responsibilities, and metrics of a service provided by one party to another. An SLA can help align the security team's objectives and activities with the business units' needs and expectations, as well as establish accountability and communication channels. VerifiedReferences:
https://www.comptia.org/training/books/casp-cas-004-study-guide
,https://searchitchannel.techtarget.com/definition/service-level-agreement
NEW QUESTION # 146
A global organization's Chief Information Security Officer (CISO) has been asked to analyze the risks involved in a plan to move the organization's current MPLS-based WAN network to use commodity Internet and SD-WAN hardware. The SD-WAN provider is currently highly regarded but Is a regional provider. Which of the following is MOST likely identified as a potential risk by the CISO?
- A. The operating costs of the MPLS network are too high for the organization.
- B. Internal IT staff will not be able to properly support remote offices after the migration.
- C. The SD-WAN provider uses a third party for support.
- D. The SD-WAN provider would not be able to handle the organization's bandwidth requirements.
Answer: C
Explanation:
Explanation
SD-WAN (Software-Defined Wide Area Network) is a technology that allows organizations to use multiple, low-cost Internet connections to create a secure and dynamic WAN. SD-WAN can provide benefits such as lower costs, higher performance, and easier management compared to traditional WAN technologies, such as MPLS (Multiprotocol Label Switching).
However, SD-WAN also introduces some potential risks, such as:
The reliability and security of the Internet connections, which may vary depending on the location, provider, and traffic conditions.
The compatibility and interoperability of the SD-WAN hardware and software, which may come from different vendors or use different standards.
The availability and quality of the SD-WAN provider's support, which may depend on the provider's size, reputation, and outsourcing practices.
In this case, the CISO would most likely identify the risk that the SD-WAN provider uses a third party for support, because this could:
Affect the organization's ability to resolve issues or request changes in a timely and effective manner.
Expose the organization's network data and configuration to unauthorized or malicious parties.
Increase the complexity and uncertainty of the SD-WAN service level agreement (SLA) and contract terms.
NEW QUESTION # 147
An organization is implementing a new identity and access management architecture with the following objectives:
Supporting MFA against on-premises infrastructure
Improving the user experience by integrating with SaaS applications
Applying risk-based policies based on location
Performing just-in-time provisioning
Which of the following authentication protocols should the organization implement to support these requirements?
- A. OTP and 802.1X
- B. Kerberos and TACACS
- C. OAuth and OpenID
- D. SAML and RADIUS
Answer: C
NEW QUESTION # 148
A cybersecurity analyst created the following tables to help determine the maximum budget amount the business can justify spending on an improved email filtering system:
Which of the following meets the budget needs of the business?
- A. Filter TUV
- B. Filter XYZ
- C. Filter GHI
- D. Filter ABC
Answer: B
Explanation:
Filter XYZ is the best option that meets the budget needs of the business. Filter XYZ has an ALE of $1 million per year, which is lower than any other filter option. ALE stands for annualized loss expectancy, which is a measure of how much money a business can expect to lose due to a risk over a year. ALE is calculated by multiplying the annualized rate of occurrence (ARO) of an event by the single loss expectancy (SLE) of an event. ARO is how often an event is expected to occur in a year. SLE is how much money an event will cost each time it occurs. Therefore, ALE = ARO x SLE. Filter XYZ has an ARO of 0.1 and an SLE of $10 million, so ALE = 0.1 x $10 million = $1 million.
NEW QUESTION # 149
A company is implementing a new secure identity application, given the following requirements:
- The cryptographic secrets used in the application must never be
exposed to users or the OS
- The application must work on mobile devices.
- The application must work with the company's badge reader system
Which of the following mobile device specifications are required for this design? (Choose two.)
- A. SEAndroid
- B. UEFI
- C. Biometrics
- D. HSM
- E. Secure element
- F. NFC
Answer: C,F
NEW QUESTION # 150
A recent security assessment generated a recommendation to transition Wi-Fi to WPA2/WPA3 Enterprise requiring EAP-TLS. Which of the following conditions must be met for the organization's mobile devices to be able to successfully join the corporate wireless network?
- A. The device's IPSec configuration matches the VPN concentrator.
- B. Supplicants are configured to provide a 64-bit authenticator.
- C. Client computer X.509 certificates have been installed.
- D. A hardware TOTP token has been issued to mobile users.
Answer: C
Explanation:
For an organization transitioning its Wi-Fi to WPA2/WPA3 Enterprise with EAP-TLS, X.509 certificates are crucial. EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) is a certificate-based authentication protocol, and for it to work, both the client and server must have valid X.509 certificates. This ensures that the mobile devices can authenticate themselves securely to the wireless network. Other options like IPSec configurations or TOTP tokens are not relevant in the context of EAP-TLS wireless authentication.
CASP+ highlights the importance of certificate management in secure wireless authentication protocols.
References:
* CASP+ CAS-004 Exam Objectives: Domain 3.0 - Enterprise Security Architecture (Wireless Authentication and EAP-TLS)
* CompTIA CASP+ Study Guide: Certificate Management for EAP-TLS
NEW QUESTION # 151
A company that all mobile devices be encrypted, commensurate with the full disk encryption scheme of assets, such as workstation, servers, and laptops. Which of the following will MOST likely be a limiting factor when selecting mobile device managers for the company?
- A. Inability to selected AES-256 encryption
- B. Removal of user authentication requirements
- C. Increased network latency
- D. Unavailable of key escrow
Answer: A
Explanation:
The inability to select AES-256 encryption will most likely be a limiting factor when selecting mobile device managers for the company. AES-256 is a symmetric encryption algorithm that uses a 256-bit key to encrypt and decrypt data. It is considered one of the strongest encryption methods available and is widely used for securing sensitive data. Mobile device managers are software applications that allow administrators to remotely manage and secure mobile devices used by employees. However, not all mobile device managers may support AES-256 encryption or allow the company to enforce it as a policy on all mobile devices. Verified Reference: https://www.comptia.org/training/books/casp-cas-004-study-guide , https://searchmobilecomputing.techtarget.com/definition/mobile-device-management
NEW QUESTION # 152
A security manager has written an incident response playbook for insider attacks and is ready to begin testing it. Which of the following should the manager conduct to test the playbook?
- A. Threat emulation
- B. Automated vulnerability scanning
- C. Threat hunting
- D. Centralized logging, data analytics, and visualization
Answer: A
Explanation:
Explanation
Threat emulation is the method that should be used to test an incident response playbook for insider attacks.
Threat emulation is a technique that simulates real-world attacks using realistic scenarios, tactics, techniques, and procedures (TTPs) of threat actors. Threat emulation can help evaluate the effectiveness of an incident response plan by testing how well it can detect, respond to, contain, eradicate, recover from, and learn from an attack.
References: [CompTIA CASP+ Study Guide, Second Edition, page 461]
NEW QUESTION # 153
A threat hunting team receives a report about possible APT activity in the network.
Which of the following threat management frameworks should the team implement?
- A. MITRE ATT&CK
- B. The Cyber Kill Chain
- C. NIST SP 800-53
- D. The Diamond Model of Intrusion Analysis
Answer: A
Explanation:
Explanation
MITRE ATT&CK is a threat management framework that provides a comprehensive and detailed knowledge base of adversary tactics and techniques based on real-world observations. It can help threat hunting teams to identify, understand, and prioritize potential threats, as well as to develop effective detection and response strategies. MITRE ATT&CK covers the entire lifecycle of a cyberattack, from initial access to impact, and provides information on how to mitigate, detect, and hunt for each technique. It also includes threat actor profiles, software descriptions, and data sources that can be used for threat intelligence and analysis. Verified References:
https://attack.mitre.org/
https://resources.infosecinstitute.com/topic/top-threat-modeling-frameworks-stride-owasp-top-10-mitre-att
https://www.ibm.com/topics/threat-management
NEW QUESTION # 154
A company with only U S -based customers wants to allow developers from another country to work on the company's website However, the company plans to block normal internet traffic from the other country Which of the following strategies should the company use to accomplish this objective? (Select two).
- A. Block foreign IP addresses from accessing the website
- B. Implement a WAP for the website
- C. Employ a reverse proxy for the developers
- D. Use NAT to enable access for the developers
- E. Have the developers use the company's VPN
- F. Give the developers access to a jump box on the network
Answer: E,F
Explanation:
Having developers use the company's VPN can provide them with secure access to the network while still allowing the company to block normal internet traffic from the other country. A jump box serves as a secure entry point for administrators or in this case, developers, to connect before launching any administrative tasks or accessing further areas of the network. This setup maintains security while still providing necessary access.
NEW QUESTION # 155
A security architect was asked to modify an existing internal network design to accommodate the following requirements for RDP:
* Enforce MFA for RDP
* Ensure RDP connections are only allowed with secure ciphers.
The existing network is extremely complex and not well segmented. Because of these limitations, the company has requested that the connections not be restricted by network-level firewalls Of ACLs.
Which of the following should the security architect recommend to meet these requirements?
- A. Implement a GPO that enforces TLS cipher suites and limits remote desktop access to only VPN users.
- B. Implement a remote desktop gateway server, enforce secure ciphers, and configure to use OTP
- C. Implement a reverse proxy for remote desktop with a secure cipher configuration enforced.
- D. Implement a bastion host with a secure cipher configuration enforced.
Answer: B
Explanation:
A remote desktop gateway server is a solution that allows users to connect to remote desktops or applications over the internet using the Remote Desktop Protocol (RDP). A remote desktop gateway server can enforce MFA for RDP by integrating with Azure AD MFA using the Network Policy Server (NPS) extension. The NPS extension can send an OTP (one-time password) to the user's phone or mobile app as a second factor of authentication. A remote desktop gateway server can also enforce secure ciphers by configuring the SSL Cipher Suite Order Group Policy setting to specify the preferred order of cipher suites for TLS/SSL connections. Verified References:
* https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-plan-access-from- anywhere
* https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-rdg
* https://docs.microsoft.com/en-us/windows-server/security/tls/tls-registry-settings#ssl-cipher-suite-order
NEW QUESTION # 156
A security administrator is trying to securely provide public access to specific data from a web application.
Clients who want to access the application will be required to:
* Only allow the POST and GET options.
* Transmit all data secured with TLS 1.2 or greater.
* Use specific URLs to access each type of data that is requested.
* Authenticate with a bearer token.
Which of the following should the security administrator recommend to meet these requirements?
- A. Reverse proxy
- B. API gateway
- C. Web application firewall
- D. Application load balancer
Answer: B
Explanation:
An API gateway is the best solution to meet the specified requirements for securely providing public access to specific data. An API gateway allows the administrator to control HTTP methods like POST and GET, ensure secure transmission via TLS 1.2 or greater, and enforce authentication using bearer tokens. It also allows access control by specifying URLs for different types of data. API gateways centralize security and traffic management for APIs, making them ideal for this type of secure access scenario. CASP+ emphasizes the importance of API gateways in managing and securing web application interfaces.
References:
* CASP+ CAS-004 Exam Objectives: Domain 3.0 - Enterprise Security Architecture (API Security and API Gateways)
* CompTIA CASP+ Study Guide: Securing Web Application Interfaces with API Gateways
NEW QUESTION # 157
......
Pass Your CompTIA Exam with CAS-004 Exam Dumps: https://www.exam4free.com/CAS-004-valid-dumps.html
CAS-004 Exam Dumps - CompTIA Practice Test Questions: https://drive.google.com/open?id=1j1z3T2mBA8bbovR50sbCBHzGBR31IxNu
