[2022] Pass CompTIA CAS-004 Exam in First Attempt Easily
The Most Efficient CAS-004 Pdf Dumps For Assured Success
CompTIA CAS-004 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
NEW QUESTION 39
An energy company is required to report the average pressure of natural gas used over the past quarter. A PLC sends data to a historian server that creates the required reports.
Which of the following historian server locations will allow the business to get the required reports in an and IT environment?
- A. Use a screened subnet between the and IT environments.
- B. In the IT environment, allow PLCs to send data from the environment to the IT environment.
- C. In the environment, allow IT traffic into the environment.
- D. In the environment, use a VPN from the IT environment into the environment.
Answer: B
NEW QUESTION 40
The Chief information Officer (CIO) wants to implement enterprise mobility throughout the organization. The goal is to allow employees access to company resources. However the CIO wants the ability to enforce configuration settings, manage data, and manage both company-owned and personal devices. Which of the following should the CIO implement to achieve this goal?
- A. BYOO
- B. CYOD
- C. COPE
- D. MDM
Answer: A
NEW QUESTION 41
An organization is planning for disaster recovery and continuity of operations.
INSTRUCTIONS
Review the following scenarios and instructions. Match each relevant finding to the affected host.
After associating scenario 3 with the appropriate host(s), click the host to select the appropriate corrective action for that finding.
Each finding may be used more than once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Answer:
Explanation:
NEW QUESTION 42
An organization recently started processing, transmitting, and storing its customers' credit card information.
Within a week of doing so, the organization suffered a massive breach that resulted in the exposure of the customers' information.
Which of the following provides the BEST guidance for protecting such information while it is at rest and in transit?
- A. GDPR
- B. PCI DSS
- C. NIST
- D. ISO
Answer: B
NEW QUESTION 43
Clients are reporting slowness when attempting to access a series of load-balanced APIs that do not require authentication. The servers that host the APIs are showing heavy CPU utilization. No alerts are found on the WAFs sitting in front of the APIs.
Which of the following should a security engineer recommend to BEST remedy the performance issues in a timely manner?
- A. Implement input validation on the API.
- B. Implement rate limiting on the API.
- C. Implement geoblocking on the WAF.
- D. Implement OAuth 2.0 on the API.
Answer: D
NEW QUESTION 44
A security compliance requirement states that specific environments that handle sensitive data must be protected by need-to-know restrictions and can only connect to authorized endpoints. The requirement also states that a DLP solution within the environment must be used to control the data from leaving the environment.
Which of the following should be implemented for privileged users so they can support the environment from their workstations while remaining compliant?
- A. A general VPN solution to the primary network
- B. NAC to control authorized endpoints
- C. A jump box in the screened subnet
- D. FIM on the servers storing the data
Answer: B
Explanation:
Network Access Control (NAC) is used to bolster the network security by restricting the availability of network resources to managed endpoints that don't satisfy the compliance requirements of the Organization.
NEW QUESTION 45
An e-commerce company is running a web server on premises, and the resource utilization is usually less than
30%. During the last two holiday seasons, the server experienced performance issues because of too many connections, and several customers were not able to finalize purchase orders. The company is looking to change the server configuration to avoid this kind of performance issue.
Which of the following is the MOST cost-effective solution?
- A. Upgrade the server with a new one.
- B. Buy a new server and create an active-active cluster.
- C. Change the operating system.
- D. Move the server to a cloud provider.
Answer: D
NEW QUESTION 46
A developer wants to develop a secure external-facing web application. The developer is looking for an online community that produces tools, methodologies, articles, and documentation in the field of
web-application security Which of the following is the BEST option?
- A. CSA
- B. OWASP
- C. ICANN
- D. PCI DSS
- E. NIST
Answer: B
NEW QUESTION 47
A security engineer thinks the development team has been hard-coding sensitive environment variables in its code.
Which of the following would BEST secure the company's CI/CD pipeline?
- A. Utilizing a trusted secrets manager
- B. Introducing the use of container orchestration
- C. Deploying instance tagging
- D. Performing DAST on a weekly basis
Answer: A
NEW QUESTION 48
Clients are reporting slowness when attempting to access a series of load-balanced APIs that do not require authentication. The servers that host the APIs are showing heavy CPU utilization. No alerts are found on the WAFs sitting in front of the APIs.
Which of the following should a security engineer recommend to BEST remedy the performance issues in a timely manner?
- A. Implement input validation on the API.
- B. Implement OAuth 2.0 on the API.
- C. Implement rate limiting on the API.
- D. Implement geoblocking on the WAF.
Answer: C
NEW QUESTION 49
A company's Chief Information Officer wants to Implement IDS software onto the current system's architecture to provide an additional layer of security. The software must be able to monitor system activity, provide Information on attempted attacks, and provide analysis of malicious activities to determine the processes or users Involved. Which of the following would provide this information?
- A. UEBA
- B. HlDS
- C. HIPS
- D. NIDS
Answer: A
NEW QUESTION 50
Which of the following terms refers to the delivery of encryption keys to a CASB or a third-party entity?
- A. Key sharing
- B. Key escrow
- C. Key distribution
- D. Key recovery
Answer: B
NEW QUESTION 51
An organization mat provides a SaaS solution recently experienced an incident involving customer data loss. The system has a level of sell-healing that includes monitoring performance and available resources. When me system detects an issue, the self-healing process is supposed to restart pans of me software.
During the incident, when me self-healing system attempted to restart the services, available disk space on the data drive to restart all the services was inadequate. The self-healing system did not detect that some services did not fully restart and declared me system as fully operational. Which of the following BEST describes me reason why the silent failure occurred?
- A. The number of nodes in me self-healing cluster was healthy,
- B. The disk utilization alarms are higher than what me service restarts require.
- C. The system logs rotated prematurely.
- D. Conditional checks prior to the service restart succeeded.
Answer: D
NEW QUESTION 52
A financial institution has several that currently employ the following controls:
* The severs follow a monthly patching cycle.
* All changes must go through a change management process.
* Developers and systems administrators must log into a jumpbox to access the servers hosting the data using two-factor authentication.
* The servers are on an isolated VLAN and cannot be directly accessed from the internal production network.
An outage recently occurred and lasted several days due to an upgrade that circumvented the approval process. Once the security team discovered an unauthorized patch was installed, they were able to resume operations within an hour. Which of the following should the security administrator recommend to reduce the time to resolution if a similar incident occurs in the future?
- A. Require more than one approver for all change management requests.
- B. Enhanced audit logging on the jump servers and ship the logs to the SIEM.
- C. Disable automatic patch update capabilities on the servers
- D. Implement file integrity monitoring with automated alerts on the servers.
Answer: D
NEW QUESTION 53
An organization is preparing to migrate its production environment systems from an on-premises environment to a cloud service. The lead security architect is concerned that the organization's current methods for addressing risk may not be possible in the cloud environment.
Which of the following BEST describes the reason why traditional methods of addressing risk may not be possible in the cloud?
- A. Migrating operations assumes the acceptance of all risk.
- B. Cloud providers are unable to avoid risk.
- C. Specific risks cannot be transferred to the cloud provider.
- D. Risks to data in the cloud cannot be mitigated.
Answer: D
NEW QUESTION 54
A company is looking for a solution to hide data stored in databases. The solution must meet the following requirements:
Be efficient at protecting the production environment
Not require any change to the application
Act at the presentation layer
Which of the following techniques should be used?
- A. Tokenization
- B. Random substitution
- C. Masking
- D. Algorithmic
Answer: C
NEW QUESTION 55
A security architect was asked to modify an existing internal network design to accommodate the following requirements for RDP:
* Enforce MFA for RDP
* Ensure RDP connections are only allowed with secure ciphers.
The existing network is extremely complex and not well segmented. Because of these limitations, the company has requested that the connections not be restricted by network-level firewalls Of ACLs.
Which of the following should the security architect recommend to meet these requirements?
- A. Implement a bastion host with a secure cipher configuration enforced.
- B. Implement a GPO that enforces TLS cipher suites and limits remote desktop access to only VPN users.
- C. Implement a reverse proxy for remote desktop with a secure cipher configuration enforced.
- D. Implement a remote desktop gateway server, enforce secure ciphers, and configure to use OTP
Answer: C
NEW QUESTION 56
A cybersecurity analyst created the following tables to help determine the maximum budget amount the business can justify spending on an improved email filtering system:

Which of the following meets the budget needs of the business?
- A. Filter XYZ
- B. Filter ABC
- C. Filter TUV
- D. Filter GHI
Answer: D
NEW QUESTION 57
A security analyst detected a malicious PowerShell attack on a single server. The malware used the Invoke-Expression function to execute an external malicious script. The security analyst scanned the disk with an antivirus application and did not find any IOCs. The security analyst now needs to deploy a protection solution against this type of malware.
Which of the following BEST describes the type of malware the solution should protect against?
- A. Worm
- B. Rootkit
- C. Fileless
- D. Logic bomb
Answer: C
NEW QUESTION 58
A Chief information Security Officer (CISO) is developing corrective-action plans based on the following from a vulnerability scan of internal hosts:
Which of the following MOST appropriate corrective action to document for this finding?
- A. The application developer should use a static code analysis tool to ensure any application code is not vulnerable to buffer overflows.
- B. The security operations center should develop a custom IDS rule to prevent attacks buffer overflows against this server.
- C. The system administrator should evaluate dependencies and perform upgrade as necessary.
- D. The product owner should perform a business impact assessment regarding the ability to implement a WAF.
Answer: D
NEW QUESTION 59
A system administrator at a medical imaging company discovers protected health information (PHI) on a general-purpose file server. Which of the following steps should the administrator take NEXT?
- A. Isolate all of the PHI on its own VLAN and keep it segregated at Layer 2.
- B. Take an MD5 hash of the server.
- C. Delete all PHI from the network until the legal department is consulted.
- D. Consult the legal department to determine the legal requirements.
Answer: A
NEW QUESTION 60
A cybersecurity analyst created the following tables to help determine the maximum budget amount the business can justify spending on an improved email filtering system:

Which of the following meets the budget needs of the business?
- A. Filter XYZ
- B. Filter ABC
- C. Filter TUV
- D. Filter GHI
Answer: D
NEW QUESTION 61
......
We offers you the latest free online CAS-004 dumps to practice: https://www.validexam.com/CAS-004-latest-dumps.html
CompTIA CAS-004 Real Exam Questions Guaranteed Updated Dump: https://drive.google.com/open?id=1lGXbZ_HMi8USSrgrKW1gkNeln48BjamK