CAS-004 Exam Details

  • Exam Code
    :CAS-004
  • Exam Name
    :CompTIA Advanced Security Practitioner (CASP+)
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :792 Q&As
  • Last Updated
    :May 28, 2026

CompTIA CAS-004 Online Questions & Answers

  • Question 451:

    A security analyst has concerns about malware on an endpoint. The malware is unable to detonate by modifying the kernel response to various system calls. As a test, the analyst modifies a Windows server to respond to system calls as if it was a Linux server. In another test, the analyst modifies the operating system to prevent the malware from identifying target files. Which of the following techniques is the analyst MOST likely using?

    A. Honeypot
    B. Deception
    C. Simulators
    D. Sandboxing

  • Question 452:

    A small business would like to provide guests who are using mobile devices encrypted WPA3 access without first distributing PSKs or other credentials. Which of the following features will enable the business to meet this objective?

    A. Simultaneous Authentication of Equals
    B. Enhanced open
    C. Perfect forward secrecy
    D. Extensible Authentication Protocol

  • Question 453:

    Which of the following objectives BEST supports leveraging tabletop exercises in business continuity planning?

    A. Determine the optimal placement of hot/warm sites within the enterprise architecture.
    B. Create new processes for identified gaps in continuity planning.
    C. Establish new staff roles and responsibilities for continuity of operations.
    D. Assess the effectiveness of documented processes against a realistic scenario.

  • Question 454:

    A Chief Security Officer (CSO) is concerned about the number of successful ransomware attacks that have hit the company. The data indicates most of the attacks came through a fake email. The company has added training, and the CSO now wants to evaluate whether the training has been successful. Which of the following should the CSO implement?

    A. Simulating a spam campaign
    B. Conducting a sanctioned vishing attack
    C. Performing a risk assessment
    D. Executing a penetration test

  • Question 455:

    An architect is designing security scheme for an organization that is concerned about APTs. Any proposed architecture must meet the following requirements:

    1.Services must be able to be reconstituted quickly from a known-good state.

    2.Network services must be designed to ensure multiple diverse layers of redundancy.

    3.Defensive and responsive actions must be automated to reduce human operator demands.

    Which of the following designs must be considered to ensure the architect meets these requirements? (Choose three.)

    A. Increased efficiency by embracing advanced caching capabilities
    B. Geographic distribution of critical data and services
    C. Hardened and verified container usage
    D. Emulated hardware architecture usage
    E. Establishment of warm and hot sites for continuity of operations
    F. Heterogeneous architecture
    G. Deployment of IPS services that can identify and block malicious traffic
    H. Implementation and configuration of a SOAR

  • Question 456:

    In a shared responsibility model for PaaS, which of the following is a customer's responsibility?

    A. Network security
    B. Physical security
    C. OS security
    D. Host infrastructure

  • Question 457:

    After a lengthy exercise manually analyzing various types of logs related to a security breach, a security team was able to tie the activity to specific employees.

    Which of the following should the team implement to help streamline this process moving forward?

    A. UEBA
    B. HSM
    C. HIPS
    D. XDR
    E. OPSEC training

  • Question 458:

    A security analyst is reviewing the following output:

    Which of the following would BEST mitigate this type of attack?

    A. Installing a network firewall
    B. Placing a WAF inline
    C. Implementing an IDS
    D. Deploying a honeypot

  • Question 459:

    An organization developed a containerized application. The organization wants to run the application in the cloud and automatically scale it based on demand. The security operations team would like to use container orchestration but does not want to assume patching responsibilities. Which of the following service models best meets these requirements?

    A. PaaS
    B. SaaS
    C. IaaS
    D. MaaS

  • Question 460:

    An organization recently experienced a ransomware attack. The security team leader is concerned about the attack reoccurring. However, no further security measures have been implemented. Which of the following processes can be used to identify potential prevention recommendations?

    A. Detection
    B. Remediation
    C. Preparation
    D. Recovery

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-004 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.