CompTIA CAS-004 Cert Guide PDF 100% Cover Real Exam Questions
Pass CAS-004 Exam - Real Questions and Answers
CompTIA CAS-004 Exam Syllabus Topics:
| Topic | Details |
|---|---|
Security Architecture 29% | |
| Given a scenario, analyze the security requirements and objectives to ensure an appropriate, secure network architecture for a new or existing network. | - Services
|
| Given a scenario, analyze the organizational requirements to determine the proper infrastructure security design. | - Scalability
- Resiliency
- Automation
- Containerization - Virtualization - Content delivery network - Caching |
| Given a scenario, integrate software applications securely into an enterprise architecture. | - Baseline and templates
|
| Given a scenario, implement data security techniques for securing enterprise architecture. | - Data loss prevention
- Encrypted vs. unencrypted - Data life cycle
- Data integrity management - Data storage, backup, and recovery
|
| Given a scenario, analyze the security requirements and objectives to provide the appropriate authentication and authorization controls. | - Credential management
- Password policies
- Federation
- One-time password (OTP)
|
| Given a set of requirements, implement secure cloud and virtualization solutions. | - Virtualization strategies
- Middleware - Metadata and tags - Deployment models and considerations
- Service models
- Cloud provider limitations
- Storage models
|
| Explain how cryptography and public key infrastructure (PKI) support security objectives and requirements. | - Privacy and confidentiality requirements - Integrity requirements - Non-repudiation - Compliance and policy requirements - Common cryptography use cases
- Common PKI use cases
|
| Explain the impact of emerging technologies on enterprise security and privacy. | - Artificial intelligence - Machine learning - Quantum computing - Blockchain - Homomorphic encryption
- Secure multiparty computation
-Biometric impersonation |
Security Operations 30% | |
| Given a scenario, perform threat management activities. | - Intelligence types
- Actor types
- Threat actor properties
- Intelligence collection methods
|
| Given a scenario, analyze indicators of compromise and formulate an appropriate response. | - Indicators of compromise
- Response
|
| Given a scenario, perform vulnerability management activities. | - Vulnerability scans
- Patch management - Information sources
|
| Given a scenario, use the appropriate vulnerability assessment and penetration testing methods and tools. | - Methods
- Tools
- Dependency management
|
| Given a scenario, analyze vulnerabilities and recommend risk mitigations. | - Vulnerabilities
- Inherently vulnerable system/application
|
NEW QUESTION 75
A junior developer is informed about the impact of new malware on an Advanced RISC Machine (ARM) CPU, and the code must be fixed accordingly. Based on the debug, the malware is able to insert itself in another process memory location.
Which of the following technologies can the developer enable on the ARM architecture to prevent this type of malware?
- A. Virtual memory encryption
- B. No-execute
- C. Total memory encryption
- D. Execute never
Answer: D
NEW QUESTION 76
Ransomware encrypted the entire human resources fileshare for a large financial institution. Security operations personnel were unaware of the activity until it was too late to stop it. The restoration will take approximately four hours, and the last backup occurred 48 hours ago. The management team has indicated that the RPO for a disaster recovery event for this data classification is 24 hours.
Based on RPO requirements, which of the following recommendations should the management team make?
- A. Leave the current backup schedule intact and make the human resources fileshare read-only.
- B. Decrease the frequency of backups and pay the ransom to decrypt the data.
- C. Increase the frequency of backups and create SIEM alerts for IOCs.
- D. Leave the current backup schedule intact and pay the ransom to decrypt the data.
Answer: C
NEW QUESTION 77
A company that all mobile devices be encrypted, commensurate with the full disk encryption scheme of assets, such as workstation, servers, and laptops. Which of the following will MOST likely be a limiting factor when selecting mobile device managers for the company?
- A. Inability to selected AES-256 encryption
- B. Increased network latency
- C. Unavailable of key escrow
- D. Removal of user authentication requirements
Answer: B
NEW QUESTION 78
A company that uses AD is migrating services from LDAP to secure LDAP. During the pilot phase, services are not connecting properly to secure LDAP. Block is an except of output from the troubleshooting session:
Which of the following BEST explains why secure LDAP is not working? (Select TWO.)
- A. The company is using the wrong port. It should be using port 389 for secure LDAP.
- B. Secure LDAP should be running on UDP rather than TCP.
- C. The clients may not trust idapt by default.
- D. Secure LDAP does not support wildcard certificates.
- E. Danvills.com is under a DDoS-inator attack and cannot respond to OCSP requests.
- F. The secure LDAP service is not started, so no connections can be made.
- G. The clients may not trust Chicago by default.
Answer: A,F
NEW QUESTION 79
A threat analyst notices the following URL while going through the HTTP logs.
Which of the following attack types is the threat analyst seeing?
- A. CSRF
- B. SQL injection
- C. XSS
- D. Session hijacking
Answer: C
NEW QUESTION 80
Device event logs sources from MDM software as follows:
Which of the following security concerns and response actions would BEST address the risks posed by the device in the logs?
- A. Malicious installation of an application; change the MDM configuration to remove application ID 1220.
- B. Resource leak; recover the device for analysis and clean up the local storage.
- C. Impossible travel; disable the device's account and access while investigating.
- D. Falsified status reporting; remotely wipe the device.
Answer: A
NEW QUESTION 81
Which of the following are risks associated with vendor lock-in? (Choose two.)
- A. The client can seamlessly move data.
- B. The vendor can change product offerings.
- C. The client can leverage a multicloud approach.
- D. The client receives a sufficient level of service.
- E. The client experiences increased interoperability.
- F. The client experiences decreased quality of service.
Answer: B,F
NEW QUESTION 82
During a remodel, a company's computer equipment was moved to a secure storage room with cameras positioned on both sides of the door. The door is locked using a card reader issued by the security team, and only the security team and department managers have access to the room. The company wants to be able to identify any unauthorized individuals who enter the storage room by following an authorized employee.
Which of the following processes would BEST satisfy this requirement?
- A. Require department managers to review denied-access requests.
- B. Monitor camera footage corresponding to a valid access request.
- C. Issue new entry badges on a weekly basis.
- D. Require both security and management to open the door.
Answer: B
NEW QUESTION 83
A developer implement the following code snippet.
Which of the following vulnerabilities does the code snippet resolve?
- A. Information leakage
- B. Buffer overflow
- C. Missing session limit
- D. SQL inject
Answer: A
NEW QUESTION 84
A company's claims processed department has a mobile workforce that receives a large number of email submissions from personal email addresses. An employees recently received an email that approved to be claim form, but it installed malicious software on the employee's laptop when was opened.
- A. Required all laptops to connect to the VPN before accessing email.
- B. Impalement application whitelisting and add only the email client to the whitelist for laptop in the claims processing department.
- C. Implement cloud-based content filtering with sandboxing capabilities.
- D. Install a mail gateway to scan incoming messages and strip attachments before they reach the mailbox.
Answer: C
NEW QUESTION 85
The Chief information Officer (CIO) asks the system administrator to improve email security at the company based on the following requirements:
* Transaction being requested by unauthorized individuals.
* Complete discretion regarding client names, account numbers, and investment information.
* Malicious attackers using email to malware and ransomeware.
* Exfiltration of sensitive company information.
The cloud-based email solution will provide anti-malware reputation-based scanning, signature-based scanning, and sandboxing. Which of the following is the BEST option to resolve the boar's concerns for this email migration?
- A. SSL VPN
- B. Endpoint detection response
- C. Application whitelisting
- D. Data loss prevention
Answer: D
NEW QUESTION 86
An e-commerce company is running a web server on premises, and the resource utilization is usually less than 30%. During the last two holiday seasons, the server experienced performance issues because of too many connections, and several customers were not able to finalize purchase orders. The company is looking to change the server configuration to avoid this kind of performance issue.
Which of the following is the MOST cost-effective solution?
- A. Upgrade the server with a new one.
- B. Move the server to a cloud provider.
- C. Change the operating system.
- D. Buy a new server and create an active-active cluster.
Answer: B
NEW QUESTION 87
A company hired a third party to develop software as part of its strategy to be quicker to market. The company's policy outlines the following requirements:
The credentials used to publish production software to the container registry should be stored in a secure location.
Access should be restricted to the pipeline service account, without the ability for the third-party developer to read the credentials directly.
Which of the following would be the BEST recommendation for storing and monitoring access to these shared credentials?
- A. TPM
- B. Key vault
- C. MFA
- D. Local secure password file
Answer: A
NEW QUESTION 88
During a system penetration test, a security engineer successfully gained access to a shell on a Linux host as a standard user and wants to elevate the privilege levels.
Which of the following is a valid Linux post-exploitation method to use to accomplish this goal?
- A. Perform ASIC password cracking on the host.
- B. Use the UNION operator to extract the database schema.
- C. Spawn a shell using sudo and an escape string such as sudo vim -c '!sh'.
- D. Initiate unquoted service path exploits.
- E. Read the /etc/passwd file to extract the usernames.
Answer: E
NEW QUESTION 89
A security analyst is trying to identify the source of a recent data loss incident. The analyst has reviewed all the for the time surrounding the identified all the assets on the network at the time of the data loss. The analyst suspects the key to finding the source was obfuscated in an application. Which of the following tools should the analyst use NEXT?
- A. Log reduction and analysis tool
- B. Network enurrerator
- C. Software Decomplier
- D. Static code analysis
Answer: D
NEW QUESTION 90
A company undergoing digital transformation is reviewing the resiliency of a CSP and is concerned about meeting SLA requirements in the event of a CSP incident.
Which of the following would be BEST to proceed with the transformation?
- A. An active-active solution within the same tenant
- B. A multicloud provider solution
- C. An on-premises solution as a backup
- D. A load balancer with a round-robin configuration
Answer: A
NEW QUESTION 91
A security architect is implementing a web application that uses a database back end. Prior to the production, the architect is concerned about the possibility of XSS attacks and wants to identify security controls that could be put in place to prevent these attacks.
Which of the following sources could the architect consult to address this security concern?
- A. OWASP
- B. IEEE
- C. SDLC
- D. OVAL
Answer: D
NEW QUESTION 92
A security analyst is researching containerization concepts for an organization. The analyst is concerned about potential resource exhaustion scenarios on the Docker host due to a single application that is overconsuming available resources.
Which of the following core Linux concepts BEST reflects the ability to limit resource allocation to containers?
- A. Device mapper
- B. Union filesystem overlay
- C. Cgroups
- D. Linux namespaces
Answer: C
NEW QUESTION 93
A shipping company that is trying to eliminate entire classes of threats is developing an SELinux policy to ensure its custom Android devices are used exclusively for package tracking.
After compiling and implementing the policy, in which of the following modes must the company ensure the devices are configured to run?
- A. Permissive
- B. Mandatory
- C. Enforcing
- D. Protecting
Answer: A
NEW QUESTION 94
......
100% Free CAS-004 Daily Practice Exam With 130 Questions: https://www.testvalid.com/CAS-004-exam-collection.html
Pass CAS-004 Review Guide, Reliable CAS-004 Test Engine: https://drive.google.com/open?id=1hle3b8a0MVY83YeDg_4J13S0FDbpr05U