CAS-004 Exam Details

  • Exam Code
    :CAS-004
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :792 Q&As
  • Last Updated
    :May 28, 2026

CompTIA CAS-004 Online Questions & Answers

  • Question 181:

    DRAG DROP

    Drag and drop the cloud deployment model to the associated use-case scenario. Options may be used only once or not at all.

    Select and Place:

  • Question 182:

    A business wants to migrate its workloads from an exclusively on-premises IT infrastructure to the cloud but cannot implement all the required controls. Which of the following BEST describes the risk associated with this implementation?

    A. Loss of governance
    B. Vendor lockout
    C. Compliance risk
    D. Vendor lock-in

  • Question 183:

    A company would like to move its payment card data to a cloud provider. Which of the following solutions will best protect account numbers from unauthorized disclosure?

    A. Storing the data in an encoded file
    B. Implementing database encryption at rest
    C. Only storing tokenized card data
    D. Implementing data field masking

  • Question 184:

    A small software company deployed a new web application after a network security scan found no vulnerabilities. A customer using this application reported malicious activity believed to be associated with the application. During an investigation, the company discovered that the customer closed the browser tab and connected to another application, using the same credentials on both platforms.

    Which of the following detection methods should the software company implement before deploying the next version?

    A. Multifactor authentication
    B. Static application code scanning
    C. Stronger password policy
    D. A SIEM

  • Question 185:

    A user logged in to a web application. Later, a SOC analyst noticed the user logged in to systems after normal business hours. The end user confirms the log-ins after hours were unauthorized. Following an investigation, the SOC analyst determined that the web server was running an outdated version of OpenSSL. No other suspicious user log-ins were found.

    Which of the following describes what happened and how to fix it?

    A. A downgrade attack occurred. Any use of old, outdated software should be disallowed.
    B. The attacker obtained the systems' private keys. New key pairs must be generated.
    C. Malware is present on the client machine. A full OS needs to be reinstalled.
    D. The user fell for a phishing attack. The end user must attend security training.

  • Question 186:

    A company has been the target of LDAP injections, as well as brute-force, whaling, and spear-phishing attacks. The company is concerned about ensuring continued system access. The company has already implemented a SSO system with strong passwords. Which of the following additional controls should the company deploy?

    A. Two-factor authentication
    B. Identity proofing
    C. Challenge questions
    D. Live identity verification

  • Question 187:

    A company recently deployed a SIEM and began importing logs from a firewall, a file server, a domain controller a web server, and a laptop. A security analyst receives a series of SIEM alerts and prepares to respond. The following is the alert information:

    Which of the following should the security analyst do FIRST?

    A. Disable Administrator on abc-uaa-fsl, the local account is compromised
    B. Shut down the abc-usa-fsl server, a plaintext credential is being used
    C. Disable the jdoe account, it is likely compromised
    D. Shut down abc-usa-fw01; the remote access VPN vulnerability is exploited

  • Question 188:

    The Chief Information Security Officer (CISO) is working with a new company and needs a legal "document to ensure all parties understand their roles during an assessment. Which of the following should the CISO have each party sign?

    A. SLA
    B. ISA
    C. Permissions and access
    D. Rules of engagement

  • Question 189:

    A company has moved its sensitive workloads lo the cloud and needs to ensure high availability and resiliency of its web-based application. The cloud architecture team was given the following requirements

    The application must run at 70% capacity at all times The application must sustain DoS and DDoS attacks. Services must recover automatically.

    Which of the following should the cloud architecture team implement? (Select THREE).

    A. Read-only replicas
    B. BCP
    C. Autoscaling
    D. WAF
    E. CDN
    F. Encryption
    G. Continuous snapshots
    H. Containenzation

  • Question 190:

    A security engineer is performing a routine audit of a company's decommissioned devices. The current process involves a third-party firm removing the hard drive from a company device, wiping it using a seven-pass software, placing it back

    into the device, and tagging the device for reuse or disposal. The audit reveals sensitive information is present in the hard drive cluster tips.

    Which of the following should the third-party firm implement NEXT to ensure all data is permanently removed?

    A. Degauss the drives using a commercial tool.
    B. Scramble the file allocation table
    C. Wipe the drives using a 21-pass overwrite
    D. Disable the logic board using high-voltage input

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.