CAS-004 Exam Details

  • Exam Code
    :CAS-004
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :792 Q&As
  • Last Updated
    :May 28, 2026

CompTIA CAS-004 Online Questions & Answers

  • Question 361:

    DRAG DROP

    You are an information security analyst tasked to provide feedback and remediation guidance to an organization that is working to comply with a prescriptive framework. The framework includes the following controls related to network design:

    Network hosts must be segmented into security domains.

    A screened subnet must be used for all externally available assets.

    A shared services zone must be present for internal servers and should not contain workstations.

    INSTRUCTIONS

    Based on the stated requirements, place each resource in the appropriate network location. All resources must be used, and all network zones will be filled.

    Select and Place:

  • Question 362:

    Device event logs sources from MDM software as follows: Which of the following security concerns and response actions would BEST address the risks posed by the device in the logs?

    A. Malicious installation of an application; change the MDM configuration to remove application ID 1220.
    B. Resource leak; recover the device for analysis and clean up the local storage.
    C. Impossible travel; disable the device's account and access while investigating.
    D. Falsified status reporting; remotely wipe the device.

  • Question 363:

    A security researcher detonated some malware in a lab environment and identified the following commands running from the EDR tool:

    With which of the following MITRE ATTandCK TTPs is the command associated? (Select TWO).

    A. Indirect command execution
    B. OS credential dumping
    C. Inhibit system recovery
    D. External remote services
    E. System information discovery
    F. Network denial of service

  • Question 364:

    A security analyst is reviewing suspicious emails that were forwarded by users. Which of the following is the best method for the analyst to use when reviewing attachments that came with these emails?

    A. Reverse engineering
    B. Protocol analysis
    C. Sandboxing
    D. Fuzz testing
    E. Steganography

  • Question 365:

    A network administrator who manages a Linux web server notices the following traffic:

    http://comptia.org/../../../../etc/shadow

    Which of the following is the BEST action for the network administrator to take to defend against this type of web attack?

    A. Validate the server certificate and trust chain.
    B. Validate the server input and append the input to the base directory path.
    C. Validate that the server is not deployed with default account credentials.
    D. Validate that multifactor authentication is enabled on the server for all user accounts.

  • Question 366:

    A Chief Information Security Officer is concerned about the condition of the code security being used for web applications. It is important to get the review right the first time, and the company is willing to use a tool that will allow developers to validate code as it is written. Which of the following methods should the company use?

    A. SAST
    B. DAST
    C. Fuzz testing
    D. Intercepting proxy

  • Question 367:

    A security architect is working with a new customer to find a vulnerability assessment solution that meets the following requirements:

    1.Fast scanning

    2.The least false positives possible

    3.Signature-based

    4.A low impact on servers when performing a scan

    In addition, the customer has several screened subnets, VLANs, and branch offices. Which of the following will BEST meet the customer's needs?

    A. Authenticated scanning
    B. Passive scanning
    C. Unauthenticated scanning
    D. Agent-based scanning

  • Question 368:

    Before launching a new web application, an organization would like to perform security testing. Which of the following resources should the organization use to determine the objectives for the test?

    A. CASB
    B. SOAR
    C. OWASP
    D. ISAC

  • Question 369:

    A DNS forward lookup zone named comptia.org must:

    1. Ensure the DNS is protected from on-path attacks.

    2. Ensure zone transfers use mutual authentication and are authenticated and negotiated.

    Which of the following should the security architect configure to meet these requirements? (Choose two.)

    A. Public keys
    B. Conditional forwarders
    C. Root hints
    D. DNSSEC
    E. CNAME records
    F. SRV records

  • Question 370:

    An multinational organization was hacked, and the incident response team's timely action prevented a major disaster Following the event, the team created an after action report. Which of the following is the primary goal of an after action review?

    A. To gather evidence for subsequent legal action
    B. To determine the identity of the attacker
    C. To identify ways to improve the response process
    D. To create a plan of action and milestones

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.