CAS-004 Exam Details

  • Exam Code
    :CAS-004
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :792 Q&As
  • Last Updated
    :May 28, 2026

CompTIA CAS-004 Online Questions & Answers

  • Question 211:

    A company's employees are not permitted to access company systems while traveling internationally. The company email system is configured to block logins based on geographic location, but some employees report their mobile phones

    continue to sync email while traveling.

    Which of the following is the MOST likely explanation? (Choose two.)

    A. Outdated geographic IP information
    B. Privilege escalation attack
    C. VPN on the mobile device
    D. Unrestricted email administrator accounts
    E. Client use of UDP protocols
    F. Disabled GPS on mobile devices

  • Question 212:

    A company publishes several APIs for customers and is required to use keys to segregate customer data sets. Which of the following would be BEST to use to store customer keys?

    A. A trusted platform module
    B. A hardware security module
    C. A localized key store
    D. A public key infrastructure

  • Question 213:

    A major broadcasting company that requires continuous availability to streaming content needs to be resilient against DDoS attacks. Which of the following Is the MOST important infrastructure security design element to prevent an outage?

    A. Supporting heterogeneous architecture
    B. Leveraging content delivery network across multiple regions
    C. Ensuring cloud autoscaling is in place
    D. Scaling horizontally to handle increases in traffic

  • Question 214:

    A review of the past year's attack patterns shows that attackers stopped reconnaissance after finding a susceptible system to compromise. The company would like to find a way to use this information to protect the environment while still gaining valuable attack information.

    Which of the following would be BEST for the company to implement?

    A. A WAF
    B. An IDS
    C. A SIEM
    D. A honeypot

  • Question 215:

    Which of the following industrial protocols is most likely to be found in public utility applications, such as water or electric?

    A. CIP
    B. Zigbee
    C. Modbus
    D. DNP3

  • Question 216:

    A security engineer has been informed by the firewall team that a specific Windows workstation is part of a command-and-control network. The only information the security engineer is receiving is that the traffic is occurring on a non-standard port (TCP 40322). Which of the following commands should the security engineer use FIRST to find the malicious process?

    A. tcpdump
    B. netstat
    C. tasklist
    D. traceroute
    E. ipconfig

  • Question 217:

    SIMULATION

    You are a security analyst tasked with interpreting an Nmap scan output from Company A’s privileged network.

    The company’s hardening guidelines indicate the following:

    1. There should be one primary server or service per device.

    2. Only default ports should be used.

    3. Non-secure protocols should be disabled.

    INSTRUCTIONS

    Using the Nmap output, identify the devices on the network and their roles, and any open ports that should be closed. For each device found, add a device entry to the Devices Discovered list, with the following information:

    1. The IP address of the device

    2. The primary server or service of the device

    3. The protocol(s) that should be disabled based on the hardening guidelines

    To select multiple protocols, use CTRL+CLICK.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    A. Check the answer in explanation.
    B. PlaceHoder
    C. PlaceHoder
    D. PlaceHoder

  • Question 218:

    A developer is creating a new mobile application for a company. The application uses REST API and TLS 1.2 to communicate securely with the external back-end server. Due to this configuration, the company is concerned about HTTPS interception attacks.

    Which of the following would be the BEST solution against this type of attack?

    A. Cookies
    B. Wildcard certificates
    C. HSTS
    D. Certificate pinning

  • Question 219:

    A company uses a CSP to provide a front end for its new payment system offering. The new offering is currently certified as PCI compliant. In order for the integrated solution to be compliant, the customer:

    A. must also be PCI compliant, because the risk is transferred to the provider.
    B. still needs to perform its own PCI assessment of the provider's managed serverless service.
    C. needs to perform a penetration test of the cloud provider's environment.
    D. must ensure in-scope systems for the new offering are also PCI compliant.

  • Question 220:

    A security architect must mitigate the risks from what is suspected to be an exposed, private cryptographic key. Which of the following is the BEST step to take?

    A. Revoke the certificate.
    B. Inform all the users of the certificate.
    C. Contact the company's Chief Information Security Officer.
    D. Disable the website using the suspected certificate.
    E. Alert the root CA.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.