CAS-004 PDF Dumps 2023 Exam Questions with Practice Test [Q115-Q133]

Share

CAS-004 PDF Dumps 2023 Exam Questions with Practice Test

Dumps for Free CAS-004 Practice Exam Questions

NEW QUESTION # 115
A company created an external application for its customers. A security researcher now reports that the application has a serious LDAP injection vulnerability that could be leveraged to bypass authentication and authorization.
Which of the following actions would BEST resolve the issue? (Choose two.)

  • A. Use containers.
  • B. Deploy a reverse proxy
  • C. Deploy a WAF.
  • D. Deploy a SIEM.
  • E. Patch the OS
  • F. Conduct input sanitization.
  • G. Deploy an IDS.

Answer: D,E


NEW QUESTION # 116
An organization's existing infrastructure includes site-to-site VPNs between datacenters. In the past year, a sophisticated attacker exploited a zero-day vulnerability on the VPN concentrator.
Consequently, the Chief Information Security Officer (CISO) is making infrastructure changes to mitigate the risk of service loss should another zero-day exploit be used against the VPN solution.
Which of the following designs would be BEST for the CISO to use?

  • A. Using Base64 encoding within the existing site-to-site VPN connections
  • B. Adding a second redundant layer of alternate vendor VPN concentrators
  • C. Transitioning to a container-based architecture for site-based services
  • D. Implementing IDS services with each VPN concentrator
  • E. Distributing security resources across VPN sites

Answer: B

Explanation:
If on VPN concentrator goes down due to a zero day threat, having a redundant VPN concentrator of a different vendor should keep you going.


NEW QUESTION # 117
An organization's existing infrastructure includes site-to-site VPNs between datacenters. In the past year, a sophisticated attacker exploited a zero-day vulnerability on the VPN concentrator. Consequently, the Chief Information Security Officer (CISO) is making infrastructure changes to mitigate the risk of service loss should another zero-day exploit be used against the VPN solution.
Which of the following designs would be BEST for the CISO to use?

  • A. Adding a second redundant layer of alternate vendor VPN concentrators
  • B. Using Base64 encoding within the existing site-to-site VPN connections
  • C. Transitioning to a container-based architecture for site-based services
  • D. Implementing IDS services with each VPN concentrator
  • E. Distributing security resources across VPN sites

Answer: D


NEW QUESTION # 118
Which of the following technologies allows CSPs to add encryption across multiple data storages?

  • A. Symmetric encryption
  • B. Data dispersion
  • C. Bit splitting
  • D. Homomorphic encryption

Answer: C

Explanation:
Cryptographic splitting, also known as cryptographic bit splitting or cryptographic data splitting, is a technique for securing data over a computer network. The technique involves encrypting data, splitting the encrypted data into smaller data units, distributing those smaller units to different storage locations, and then further encrypting the data at its new location.


NEW QUESTION # 119
A security analyst is performing a vulnerability assessment on behalf of a client. The analyst must define what constitutes a risk to the organization.
Which of the following should be the analyst's FIRST action?

  • A. Perform a full system penetration test to determine the vulnerabilities.
  • B. Create a full inventory of information and data assets.
  • C. Ascertain the impact of an attack on the availability of crucial resources.
  • D. Determine which security compliance standards should be followed.

Answer: D


NEW QUESTION # 120
After investigating virus outbreaks that have cost the company $1,000 per incident, the company's Chief Information Security Officer (CISO) has been researching new antivirus software solutions to use and be fully supported for the next two years. The CISO has narrowed down the potential solutions to four candidates that meet all the company's performance and capability requirements:

Using the table above, which of the following would be the BEST business-driven choice among five possible solutions?

  • A. Product B
  • B. Product E
  • C. Product D
  • D. Product C
  • E. Product A

Answer: C

Explanation:
Product E total for Solution cost and 2 years of Support Cost is $15,000 (and will have NO costs for incidents) Product D total for Solution cost and 2 years of Support Cost is $10,000, plus 2 Annual Incident costs total = $12,000


NEW QUESTION # 121
An attacker infiltrated an electricity-generation site and disabled the safety instrumented system.
Ransomware was also deployed on the engineering workstation. The environment has back-to- back firewalls separating the corporate and OT systems. Which of the following is the MOST likely security consequence of this attack?

  • A. A turbine would overheat and cause physical harm.
  • B. Data would be exfiltrated through the data diodes.
  • C. The engineers would need to go to the historian.
  • D. The SCADA equipment could not be maintained.

Answer: D

Explanation:
SCADA systems are used to monitor and control industrial processes, such as those used in electricity generation. Disabling the safety instrumented system and deploying ransomware on the engineering workstation could prevent the engineers from properly maintaining the SCADA equipment, potentially leading to operational issues and disruptions.
It is not likely that a turbine would overheat and cause physical harm (option A) as a result of this attack. The engineers may need to go to the historian (option B) to retrieve historical data for troubleshooting purposes, but this would not be a direct consequence of the attack. Data would not be exfiltrated through the data diodes (option D) as a result of this attack, as data diodes are unidirectional network connections that prevent data from being transmitted in the opposite direction. Data diodes are often used to isolate critical systems from external networks in order to prevent data exfiltration.


NEW QUESTION # 122
A shipping company that is trying to eliminate entire classes of threats is developing an SELinux policy to ensure its custom Android devices are used exclusively for package tracking.
After compiling and implementing the policy, in which of the following modes must the company ensure the devices are configured to run?

  • A. Permissive
  • B. Enforcing
  • C. Mandatory
  • D. Protecting

Answer: A


NEW QUESTION # 123
A security analyst discovered that the company's WAF was not properly configured. The main web server was breached, and the following payload was found in one of the malicious requests:

Which of the following would BEST mitigate this vulnerability?

  • A. CAPTCHA
  • B. Network intrusion prevention
  • C. Data encoding
  • D. Input validation

Answer: D


NEW QUESTION # 124
An organization recently started processing, transmitting, and storing its customers' credit card information.
Within a week of doing so, the organization suffered a massive breach that resulted in the exposure of the customers' information.
Which of the following provides the BEST guidance for protecting such information while it is at rest and in transit?

  • A. PCI DSS
  • B. ISO
  • C. NIST
  • D. GDPR

Answer: A


NEW QUESTION # 125
Technicians have determined that the current server hardware is outdated, so they have decided to throw it out.
Prior to disposal, which of the following is the BEST method to use to ensure no data remnants can be recovered?

  • A. Drive wiping
  • B. Physical destruction
  • C. Purging
  • D. Degaussing

Answer: B

Explanation:
Physical destruction is the best method to ensure no data remnants can be recovered. Drive wiping, degaussing, and purging are all methods of data erasure, but they may not be able to completely erase all data remnants. Physical destruction is the only method that can guarantee no data remains.


NEW QUESTION # 126
A security operations center analyst is investigating anomalous activity between a database server and an unknown external IP address and gathered the following data:
- dbadmin last logged in at 7:30 a.m. and logged out at 8:05 a.m.
- A persistent TCP/6667 connection to the external address was
established at 7:55 a.m. The connection is still active.
- Other than bytes transferred to keep the connection alive, only a few kilobytes of data transfer every hour since the start of the connection.
- A sample outbound request payload from PCAP showed the ASCII content:
"JOIN #community".
Which of the following is the MOST likely root cause?

  • A. The system has been hijacked for cryptocurrency mining.
  • B. A botnet Trojan is installed on the database server.
  • C. The dbadmin user is consulting the community for help via Internet Relay Chat.
  • D. A SQL injection was used to exfiltrate data from the database server.

Answer: B


NEW QUESTION # 127
Leveraging cryptographic solutions to protect data that is in use ensures the data is encrypted:

  • A. when it is passed across a local network.
  • B. by an enterprise hardware security module.
  • C. in memory during processing
  • D. when it is written to a system's solid-state drive.

Answer: A


NEW QUESTION # 128
A company's Chief Information Security Officer is concerned that the company's proposed move to the cloud could lead to a lack of visibility into network traffic flow logs within the VPC.
Which of the following compensating controls would be BEST to implement in this situation?

  • A. SIEM
  • B. HIDS
  • C. UEBA
  • D. EDR

Answer: A

Explanation:
Security information and event management (SIEM) solutions provide near realtime analysis of security alerts generated by a wide variety of network hardware, systems, and applications. SIEM platforms enhance incident detection and response capabilities by providing expanded insights into operational activity through collection, aggregation, and correlation of vast volumes of event data across the entire enterprise environmentSIEM removes much of the need to analyze individual systems by collecting log data and parsing it in a way that makes it easily searched and analyzed regardless of the underlying log format. Additionally, SIEM platforms remove much of the specialized knowledge needed to locate and analyze logs collected and stored on individual systems. For example, a security analyst can learn how to search and query for events using SIEM methods instead of learning how to interact with multiple operating systems, network devices, and/or applications to perform the same task.


NEW QUESTION # 129
A software assurance analyst reviews an SSH daemon's source code and sees the following:

Based on this code snippet, which of the following attacks is MOST likely to succeed?

  • A. Cross-site scripting
  • B. Race condition
  • C. Integer overflow
  • D. Driver shimming

Answer: C


NEW QUESTION # 130
The Chief information Officer (CIO) wants to establish a non-banding agreement with a third party that outlines the objectives of the mutual arrangement dealing with data transfers between both organizations before establishing a format partnership. Which of the follow would MOST likely be used?

  • A. SLA
  • B. NDA
  • C. MOU
  • D. OLA

Answer: C


NEW QUESTION # 131
A company is looking for a solution to hide data stored in databases. The solution must meet the following requirements:
Be efficient at protecting the production environment

Not require any change to the application

Act at the presentation layer

Which of the following techniques should be used?

  • A. Tokenization
  • B. Masking
  • C. Random substitution
  • D. Algorithmic

Answer: B

Explanation:
Masking is a technique for obscuring sensitive data in a database by replacing it with fictitious data that has the same format and structure as the original data. Masking can be performed at the presentation layer, which means that it does not require any changes to the application itself.
This makes it an efficient solution for protecting the production environment, as it can be easily implemented without disrupting the existing system.
Tokenization is a technique for replacing sensitive data with a randomly generated value (a token) that has no intrinsic meaning and cannot be used to recreate the original data.
Tokenization can be used to protect data at the presentation layer, but it typically requires changes to the application to store and retrieve the tokens.


NEW QUESTION # 132
A remote user reports the inability to authenticate to the VPN concentrator.
During troubleshooting, a security administrate captures an attempted authentication and discovers the following being presented by the user's VPN client:

Which of the following BEST describes the reason the user is unable to connect to the VPN service?

  • A. The user's certificate was created using insecure encryption algorithms
  • B. The user's certificate is not signed by the VPN service provider
  • C. The user's certificate was not created for VPN use
  • D. The user's certificate has been compromised and should be revoked.

Answer: D


NEW QUESTION # 133
......


The CASP+ certification exam covers a wide range of security topics, including enterprise security architecture, security operations and incident response, research and analysis, and integration of computing, communications, and business disciplines. CAS-004 exam also covers the latest technologies and trends in the security industry, such as cloud security, mobile security, and virtualization security. CAS-004 exam consists of 90 multiple-choice and performance-based questions, and the time limit is 165 minutes.

 

Check your preparation for CompTIA CAS-004 On-Demand Exam: https://www.testinsides.top/CAS-004-dumps-review.html

CAS-004 Dumps PDF And Certification Training: https://drive.google.com/open?id=1_btvApKmIJj5BFTekwdNbFb_0l1GVzeK