CAS-004 Exam Details

  • Exam Code
    :CAS-004
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :792 Q&As
  • Last Updated
    :May 28, 2026

CompTIA CAS-004 Online Questions & Answers

  • Question 241:

    A security engineer needs to ensure production containers are automatically scanned for vulnerabilities before they are accepted into the production environment.

    Which of the following should the engineer use to automatically incorporate vulnerability scanning on every commit?

    A. Code repository
    B. CI/CD pipeline
    C. Integrated development environment
    D. Container orchestrator

  • Question 242:

    An ASIC manufacturer wishing to best reduce downstream supply chain risk can provide validation instructions for consumers that:

    A. Leverage physically uncloneable functions.
    B. Analyze an emplaced holographic icon on the board.
    C. Include schematics traceable via X-ray interrogation.
    D. Incorporate MD5 hashes of the ASIC design file.

  • Question 243:

    A new mandate by the corporate security team requires that all endpoints must meet a security baseline before accessing the corporate network. All servers and desktop computers are scanned by the dedicated internal scanner appliance installed in each subnet. However, remote worker laptops do not access the network regularly. Which of the following is the BEST option for the security team to ensure remote worker laptops are scanned before being granted access to the corporate network?

    A. Implement network access control to perform host validation of installed patches.
    B. Create an 802.1X implementation with certificate-based device identification.
    C. Create a vulnerability scanning subnet for remote workers to connect to on the network at headquarters.
    D. Install a vulnerability scanning agent on each remote laptop to submit scan data.

  • Question 244:

    The principal security analyst for a global manufacturer is investigating a security incident related to abnormal behavior in the ICS network. A controller was restarted as part of the troubleshooting process, and the following issue was identified

    when the controller was restarted:

    SECURE BOOT FAILED:

    FIRMWARE MISMATCH EXPECTED 0xFDC479 ACTUAL 0x79F31B

    During the investigation, this modified firmware version was identified on several other controllers at the site. The official vendor firmware versions do not have this checksum. Which of the following stages of the MITRE ATTandCK framework for

    ICS includes this technique?

    A. Evasion
    B. Persistence
    C. Collection
    D. Lateral movement

  • Question 245:

    A development team needs terminal access to preproduction servers to verify settings and enter purchased license keys. To address the team's needs, the security administrator implements the following requirements:

    1.Only trusted accounts can access the preproduction servers.

    2.Developers cannot access the preproduction servers directly from their workstations.

    3.The trusted accounts should only have access to specific preproduction servers.

    Which of the following are necessary to fulfill the security requirements? (Select two).

    A. SSL VPN
    B. NAT gateway
    C. Air gap
    D. WAF
    E. Jump box
    F. Network ACLs

  • Question 246:

    A company moved its on-premises services to the cloud. Although a recent audit verified that data throughout the cloud service is properly classified and documented, other systems are unable to act or filter based on this information. Which of the following should the company deploy to allow other cloud-based systems to consume this information?

    A. Data mapping
    B. Data labeling
    C. Log scraping
    D. Resource tagging

  • Question 247:

    A security engineer needs to implement a cost-effective authentication scheme for a new web-based application that requires:

    1.Rapid authentication

    2.Flexible authorization

    3.Ease of deployment

    4.Low cost but high functionality

    Which of the following approaches best meets these objectives?

    A. Kerberos
    B. EAP
    C. SAML
    D. OAuth
    E. TACACS+

  • Question 248:

    A security architect is advising the application team to implement the following controls in the application before it is released:

    1.Least privilege

    2.Blocklist input validation for the following characters: \<>;, ="#+

    Based on the requirements, which of the following attacks is the security architect trying to prevent?

    A. XML injection
    B. LDAP injection
    C. CSRF
    D. XSS

  • Question 249:

    A security analyst is researching containerization concepts for an organization. The analyst is concerned about potential resource exhaustion scenarios on the Docker host due to a single application that is overconsuming available resources. Which of the following core Linux concepts BEST reflects the ability to limit resource allocation to containers?

    A. Union filesystem overlay
    B. Cgroups
    C. Linux namespaces
    D. Device mapper

  • Question 250:

    A company is migrating its data center to the cloud. Some hosts had been previously isolated, but a risk assessment convinced the engineering team to reintegrate the systems. Because the systems were isolated, the risk associated with

    vulnerabilities was low.

    Which of the following should the security team recommend be performed before migrating these servers to the cloud?

    A. Performing patching and hardening
    B. Deploying host and network IDS
    C. Implementing least functionality and time-based access
    D. Creating a honeypot and adding decoy files

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.