Exam Details

  • Exam Code
    :CAS-004
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :743 Q&As
  • Last Updated
    :Apr 15, 2025

CompTIA CompTIA Certifications CAS-004 Questions & Answers

  • Question 351:

    A security architect is designing a solution for a new customer who requires significant security capabilities in its environment. The customer has provided the architect with the following set of requirements:

    Capable of early detection of advanced persistent threats. Must be transparent to users and cause no performance degradation. Allow integration with production and development networks seamlessly. Enable the security team to hunt and investigate live exploitation techniques.

    Which of the following technologies BEST meets the customer's requirements for security capabilities?

    A. Threat Intelligence

    B. Deception software

    C. Centralized logging

    D. Sandbox detonation

  • Question 352:

    A company hosts a large amount of data in blob storage for its customers. The company recently had a number of issues with this data being prematurely deleted before the scheduled backup processes could be completed. The management team has asked the security architect for a recommendation that allows blobs to be deleted occasionally, but only after a successful backup. Which of the following solutions will BEST meet this requirement?

    A. Mirror the blobs at a local data center.

    B. Enable fast recovery on the storage account.

    C. Implement soft delete for blobs.

    D. Make the blob immutable.

  • Question 353:

    A software company wants to build a platform by integrating with another company's established product. Which of the following provisions would be MOST important to include when drafting an agreement between the two companies?

    A. Data sovereignty

    B. Shared responsibility

    C. Source code escrow

    D. Safe harbor considerations

  • Question 354:

    A security engineer notices the company website allows users to select which country they reside in, such as the following example:

    hitps://mycompany.com/main.php?Country=US

    Which of the following vulnerabilities would MOST likely affect this site?

    A. SQL injection

    B. Remote file inclusion

    C. Directory traversal

    D. Unsecure references

  • Question 355:

    An organization's finance system was recently attacked. A forensic analyst is reviewing the contents of the compromised files for credit card data. Which of the following commands should

    the analyst run to BEST determine whether financial data was lost?

    A. Option A

    B. Option B

    C. Option C

    D. Option D

  • Question 356:

    A security operations center analyst is investigating anomalous activity between a database server and an unknown external IP address and gathered the following data:

    dbadmin last logged in at 7:30 a.m. and logged out at 8:05 a.m. A persistent TCP/6667 connection to the external address was established at 7:55 a.m.

    The connection is still active.

    Other than bytes transferred to keep the connection alive, only a few kilobytes of data transfer every hour since the start of the connection.

    A sample outbound request payload from PCAP showed the ASCII content:";JOIN #community".

    Which of the following is the MOST likely root cause?

    A. A SQL injection was used to exfiltrate data from the database server.

    B. The system has been hijacked for cryptocurrency mining.

    C. A botnet Trojan is installed on the database server.

    D. The dbadmin user is consulting the community for help via Internet Relay Chat.

  • Question 357:

    Users are claiming that a web server is not accessible. A security engineer logs for the site. The engineer connects to the server and runs netstat -an and receives the following output:

    Which of the following is MOST likely happening to the server?

    A. Port scanning

    B. ARP spoofing

    C. Buffer overflow

    D. Denial of service

  • Question 358:

    An administrator at a software development company would like to protect the integrity Of the company's applications with digital signatures. The developers report that the signing process keeps failing on all applications. The same key pair used for signing, however, is working properly on the website, is valid, and is issued by a trusted CA. Which of the following is MOST likely the cause of the signature failing?

    A. The NTP server is set incorrectly for the developers.

    B. The CA has included the certificate in its CRL_

    C. The certificate is set for the wrong key usage.

    D. Each application is missing a SAN or wildcard entry on the certificate.

  • Question 359:

    An organization's finance system was recently attacked. A forensic analyst is reviewing the contents Of the compromised files for credit card data.

    Which of the following commands should the analyst run to BEST determine whether financial data was lost?

    A. Option A

    B. Option B

    C. Option C

    D. Option D

  • Question 360:

    An organization is establishing a new software assurance program to vet applications before they are introduced into the production environment, Unfortunately. many Of the applications are provided only as compiled binaries. Which Of the following should the organization use to analyze these applications? (Select TWO).

    A. Regression testing

    B. SAST

    C. Third-party dependency management

    D. IDE SAST

    E. Fuzz testing

    F. IAST

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.