Exam Details

  • Exam Code
    :CAS-004
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :743 Q&As
  • Last Updated
    :Mar 22, 2025

CompTIA CompTIA Certifications CAS-004 Questions & Answers

  • Question 21:

    A security administrator is setting up a virtualization solution that needs to run services from a single host. Each service should be the only one running in its environment. Each environment needs to have its own operating system as a base but share the kernel version and properties of the running host. Which of the following technologies would best meet these requirements?

    A. Containers

    B. Type 1 hypervisor

    C. Type 2 hypervisor

    D. Virtual desktop infrastructure

    E. Emulation

  • Question 22:

    The primary advantage of an organization creating and maintaining a vendor risk registry is to:

    A. define the risk assessment methodology.

    B. study a variety of risks and review the threat landscape.

    C. ensure that inventory of potential risk is maintained.

    D. ensure that all assets have low residual risk.

  • Question 23:

    A systems engineer needs to develop a solution that uses digital certificates to allow authentication to laptops. Which of the following authenticator types would be most appropriate for the engineer to include in the design?

    A. TOTP token

    B. Device certificate

    C. Smart card

    D. Biometric

  • Question 24:

    company management elects to cancel production. Which of the following risk strategies is the company using in this scenario?

    A. Avoidance

    B. Mitigation

    C. Rejection

    D. Acceptance

  • Question 25:

    Which of the following security features do email signatures provide?

    A. Non-repudiation

    B. Body encryption

    C. Code signing

    D. Sender authentication

    E. Chain of custody

  • Question 26:

    An organization has deployed a cloud-based application that provides virtual event services globally to clients. During a typical event, thousands of users access various entry pages within a short period of time. The entry pages include sponsor-related content that is relatively static and is pulled from a database. When the first major event occurs, users report poor response time on the entry pages. Which of the following features is the most appropriate for the company to implement?

    A. Horizontal scalability

    B. Vertical scalability

    C. Containerization

    D. Static code analysis

    E. Caching

  • Question 27:

    A senior cybersecurity engineer is solving a digital certificate issue in which the CA denied certificate issuance due to failed subject identity validation. At which of the following steps within the PKI enrollment process would the denial have occurred?

    A. RA

    B. OCSP

    C. CA

    D. IdP

  • Question 28:

    A company has a website with a huge database. The company wants to ensure that a DR site could be brought online quickly in the event of a failover, and end users would miss no more than 30 minutes of data. Which of the following should the company do to meet these objectives?

    A. Build a content caching system at the DR site.

    B. Store the nightly full backups at the DR site.

    C. Increase the network bandwidth to the DR site.

    D. Implement real-time replication for the DR site.

  • Question 29:

    An organization needs to classify its systems and data in accordance with external requirements. Which of the following roles is best qualified to perform this task?

    A. Systems administrator

    B. Data owner

    C. Data processor

    D. Data custodian

    E. Data steward

  • Question 30:

    An organization's load balancers have reached end of life and have a vulnerability that will require them to be replaced. The load balancers are scheduled to be decommissioned within the next month. The management team has decided not to resolve this risk and instead allow the load balancers to remain in place until their decommission date. Which of the following risk handling techniques is the management team using?

    A. Avoid

    B. Mitigate

    C. Accept

    D. Transfer

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.