ExamGecko
Home / CompTIA / CAS-004 / List of questions
Ask Question

CompTIA CAS-004 Practice Test - Questions Answers, Page 18

List of questions

Question 171

Report Export Collapse

An HVAC contractor requested network connectivity permission to remotely support/troubleshoot equipment issues at a company location. Currently, the company does not have a process that allows vendors remote access to the corporate network Which of the following solutions represents the BEST course of action to allow the contractor access?

Add the vendor's equipment to the existing network Give the vendor access through the standard corporate VPN
Add the vendor's equipment to the existing network Give the vendor access through the standard corporate VPN
Give the vendor a standard desktop PC to attach the equipment to Give the vendor access through the standard corporate VPN
Give the vendor a standard desktop PC to attach the equipment to Give the vendor access through the standard corporate VPN
Establish a certification process for the vendor Allow certified vendors access to the VDI to monitor and maintain the HVAC equipment
Establish a certification process for the vendor Allow certified vendors access to the VDI to monitor and maintain the HVAC equipment
Create a dedicated segment with no access to the corporate network Implement dedicated VPN hardware for vendor access
Create a dedicated segment with no access to the corporate network Implement dedicated VPN hardware for vendor access
Suggested answer: D
asked 02/10/2024
Felipe Santos Cardoso
47 questions

Question 172

Report Export Collapse

Which of the following is required for an organization to meet the ISO 27018 standard?

All Pll must be encrypted.
All Pll must be encrypted.
All network traffic must be inspected.
All network traffic must be inspected.
GDPR equivalent standards must be met
GDPR equivalent standards must be met
COBIT equivalent standards must be met
COBIT equivalent standards must be met
Suggested answer: A
asked 02/10/2024
Haythem KEfi
37 questions

Question 173

Report Export Collapse

A vulnerability assessment endpoint generated a report of the latest findings. A security analyst needs to review the report and create a priority list of items that must be addressed. Which of the following should the analyst use to create the list quickly?

Business impact rating
Business impact rating
CVE dates
CVE dates
CVSS scores
CVSS scores
OVAL
OVAL
Suggested answer: A
asked 02/10/2024
Jack de Cort
43 questions

Question 174

Report Export Collapse

A security analyst is reviewing the following vulnerability assessment report:

CompTIA CAS-004 image Question 174 94142 10022024175034000000

Which of the following should be patched FIRST to minimize attacks against Internet-facing hosts?

Server1
Server1
Server2
Server2
Server 3
Server 3
Servers
Servers
Suggested answer: A
asked 02/10/2024
Stefan Hupfloher
54 questions

Question 175

Report Export Collapse

An organization is researching the automation capabilities for systems within an OT network. A security analyst wants to assist with creating secure coding practices and would like to learn about the programming languages used on the PLCs. Which of the following programming languages is the MOST relevant for PLCs?

Ladder logic
Ladder logic
Rust
Rust
C
C
Python
Python
Java
Java
Suggested answer: A
asked 02/10/2024
Anu V
35 questions

Question 176

Report Export Collapse

A company based in the United States holds insurance details of EU citizens. Which of the following must be adhered to when processing EU citizens' personal, private, and confidential data?

The principle of lawful, fair, and transparent processing
The principle of lawful, fair, and transparent processing
The right to be forgotten principle of personal data erasure requests
The right to be forgotten principle of personal data erasure requests
The non-repudiation and deniability principle
The non-repudiation and deniability principle
The principle of encryption, obfuscation, and data masking
The principle of encryption, obfuscation, and data masking
Suggested answer: A
asked 02/10/2024
Tom Nice
33 questions

Question 177

Report Export Collapse

A security architect was asked to modify an existing internal network design to accommodate the following requirements for RDP:

* Enforce MFA for RDP

* Ensure RDP connections are only allowed with secure ciphers.

The existing network is extremely complex and not well segmented. Because of these limitations, the company has requested that the connections not be restricted by network-level firewalls Of ACLs.

Which of the following should the security architect recommend to meet these requirements?

Implement a reverse proxy for remote desktop with a secure cipher configuration enforced.
Implement a reverse proxy for remote desktop with a secure cipher configuration enforced.
Implement a bastion host with a secure cipher configuration enforced.
Implement a bastion host with a secure cipher configuration enforced.
Implement a remote desktop gateway server, enforce secure ciphers, and configure to use OTP
Implement a remote desktop gateway server, enforce secure ciphers, and configure to use OTP
Implement a GPO that enforces TLS cipher suites and limits remote desktop access to only VPN users.
Implement a GPO that enforces TLS cipher suites and limits remote desktop access to only VPN users.
Suggested answer: C
Explanation:

A remote desktop gateway server is a solution that allows users to connect to remote desktops or applications over the internet using the Remote Desktop Protocol (RDP). A remote desktop gateway server can enforce MFA for RDP by integrating with Azure AD MFA using the Network Policy Server (NPS) extension. The NPS extension can send an OTP (one-time password) to the user's phone or mobile app as a second factor of authentication. A remote desktop gateway server can also enforce secure ciphers by configuring the SSL Cipher Suite Order Group Policy setting to specify the preferred order of cipher suites for TLS/SSL connections. Verified

Reference:

https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-plan-access-from-anywhere

https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-rdg

https://docs.microsoft.com/en-us/windows-server/security/tls/tls-registry-settings#ssl-cipher-suite-order

asked 02/10/2024
Oscar Ballabriga
35 questions

Question 178

Report Export Collapse

A security engineer is reviewing a record of events after a recent data breach incident that Involved the following:

* A hacker conducted reconnaissance and developed a footprint of the company s Internet-facing web application assets.

* A vulnerability in a third-party horary was exploited by the hacker, resulting in the compromise of a local account.

* The hacker took advantage of the account's excessive privileges to access a data store and exfiltrate the data without detection.

Which of the following is the BEST solution to help prevent this type of attack from being successful in the future?

Dynamic analysis
Dynamic analysis
Secure web gateway
Secure web gateway
Software composition analysis
Software composition analysis
User behavior analysis
User behavior analysis
Stateful firewall
Stateful firewall
Suggested answer: C
Explanation:

Software composition analysis (SCA) is the best solution to help prevent this type of attack from being successful in the future. SCA is a process of identifying the third-party and open source components in the applications of an organization. This analysis leads to the discovery of security risks, quality of code, and license compliance of the components. SCA can help the security engineer to detect and remediate any vulnerabilities in a third-party library that was exploited by the hacker, such as updating to a newer and more secure version of the library. SCA can also help to enforce secure coding practices and standards, such as following the principle of least privilege and avoiding excessive privileges for local accounts. By using SCA, the security engineer can improve the security posture and resilience of the web application assets against future attacks. Verified

Reference:

https://www.synopsys.com/glossary/what-is-software-composition-analysis.html

https://www.geeksforgeeks.org/overview-of-software-composition-analysis/

asked 02/10/2024
nico farina
45 questions

Question 179

Report Export Collapse

A security engineer needs 10 implement a CASB to secure employee user web traffic. A Key requirement is mat relevant event data must be collected from existing on-premises infrastructure components and consumed by me CASB to expand traffic visibility. The solution must be nighty resilient to network outages. Which of the following architectural components would BEST meet these requirements?

Log collection
Log collection
Reverse proxy
Reverse proxy
AWAF
AWAF
API mode
API mode
Suggested answer: A
asked 02/10/2024
Sergio Zozulenko
45 questions

Question 180

Report Export Collapse

The Chief information Officer (CIO) wants to implement enterprise mobility throughout the organization. The goal is to allow employees access to company resources. However the CIO wants the ability to enforce configuration settings, manage data, and manage both company-owned and personal devices. Which of the following should the CIO implement to achieve this goal?

BYOO
BYOO
CYOD
CYOD
COPE
COPE
MDM
MDM
Suggested answer: A
asked 02/10/2024
Zdenek Kugler
33 questions
Total 564 questions
Go to page: of 57
Search

Related questions