Exam Details

  • Exam Code
    :CAS-004
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :743 Q&As
  • Last Updated
    :Mar 22, 2025

CompTIA CompTIA Certifications CAS-004 Questions & Answers

  • Question 31:

    A help desk analyst suddenly begins receiving numerous calls from remote employees who state they are unable to connect to the VPN. The employees indicate the VPN client software is warning about an expired certificate. The help desk analyst determines the VPN certificate is valid. Which of the following is the most likely cause of the issue?

    A. The certificate has been compromised and needs to be replaced.

    B. The VPN concentrator is running an old version of code and needs to be upgraded.

    C. The NTP settings on the VPN concentrator are incorrectly configured.

    D. The end users are using outdated VPN client software.

  • Question 32:

    A security analyst identified a vulnerable and deprecated runtime engine that is supporting a public-facing banking application. The developers anticipate the transition to modern development environments will take at least a month. Which of the following controls would best mitigate the risk without interrupting the service during the transition?

    A. Shutting down the systems until the code is ready

    B. Uninstalling the impacted runtime engine

    C. Selectively blocking traffic on the affected port

    D. Configuring IPS and WAF with signatures

  • Question 33:

    A company has data it would like to aggregate from its PLCs for data visualization and predictive maintenance purposes. Which of the following is the most likely destination for the tag data from the PLCs?

    A. External drive

    B. Cloud storage

    C. System aggregator

    D. Local historian

  • Question 34:

    Recently, two large engineering companies in the same line of business decided to approach cyberthreats in a united way. Which of the following best describes this unified approach?

    A. NDA

    B. ISA

    C. SLA

    D. MOU

  • Question 35:

    The Chief Information Security Officer (CISO) is working with a new company and needs a legal document to ensure all parties understand their roles during an assessment. Which of the following should the CISO have each party sign?

    A. SLA

    B. ISA

    C. Permissions and access

    D. Rules of engagement

  • Question 36:

    A security officer at an organization that makes and sells digital artwork must ensure the integrity of the artwork can be maintained. Which of the following are the best ways for the security officer to accomplish this task? (Choose two.)

    A. Hashing

    B. ECC

    C. IPSec

    D. Tokenization

    E. Watermarking

    F. Print blocking

  • Question 37:

    A risk assessment determined that company data was leaked to the general public during a migration. Which of the following best explains the root cause of this issue?

    A. Incomplete firewall rules between the CSP and on-premises infrastructure

    B. Insufficient logging of cloud activities to company SIEM

    C. Failure to implement full disk encryption to on-premises data storage

    D. Misconfiguration of access controls on cloud storage containers

  • Question 38:

    Which of the following industrial protocols is most likely to be found in public utility applications, such as water or electric?

    A. CIP

    B. Zigbee

    C. Modbus

    D. DNP3

  • Question 39:

    A security analyst is reviewing suspicious emails that were forwarded by users. Which of the following is the best method for the analyst to use when reviewing attachments that came with these emails?

    A. Reverse engineering

    B. Protocol analysis

    C. Sandboxing

    D. Fuzz testing

    E. Steganography

  • Question 40:

    Following a Log4j outbreak, several network appliances were not managed and remained undetected despite an application inventory system being in place. Which of the following solutions should the security director recommend to best understand the composition of applications on unmanaged devices?

    A. Protocol analyzer

    B. Package monitoring

    C. Software bill of materials

    D. Fuzz testing

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.