CompTIA Advanced Security Practitioner (casp+) Practice Questions
Prepare for CAS-004 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 210 questions Locked
- CA1-005Legacy CompTIA SecurityX (Extended) 215 questions Locked
- CAS-003Legacy CompTIA Advanced Security Practitioner (CASP) 361 questions Locked
- CAS-004Legacy Comptia Advanced Security Practitioner (casp+) 149 questions Current
- Exam fee
- $466 USD
- Level
- Advanced/Expert
- Valid for
- 3 years
Domains covered on the exam 4
- Security Architecture29%
- Security Operations30%
- Security Engineering and Cryptography26%
- Governance, Risk, and Compliance15%
- 1
An organization is implementing a new identity and access management architecture with the following objectives:✑ Supporting MFA against on-premises infrastructure✑ Improving the user experience by integrating with SaaS applications✑ Applying risk-based policies based on location✑ Performing just-in-time provisioningWhich of the following authentication protocols should the organization implement to support these requirements?
Show answer details
Correct answer: D
- 2
Which of the following allows computation and analysis of data within a ciphertext without knowledge of the plaintext?
Show answer details
Correct answer: C
- 3
A manufacturing company needs to provide its third-party maintenance vendor with remote access to a legacy SCADA Human-Machine Interface (HMI) located in the plant's operational technology (OT) network. The OT network is physically isolated from the corporate IT network. The solution must provide secure, audited access without introducing a direct network path between IT and OT environments. Which architecture provides the MOST secure solution that meets these requirements?
graph TD subgraph IT_Network Vendor[Vendor Laptop] --> Internet((Internet)) Internet --> CorpFW[Corporate Firewall] end subgraph OT_Network HMI[SCADA HMI] end CorpFW ---|?????| HMIShow answer details
Correct answer: A
This solution aligns with the Purdue model for ICS/OT security. An Industrial DMZ (IDMZ) creates a secure buffer zone between the IT and OT networks. Placing a PAM solution in the IDMZ allows for strong authentication, fine-grained access control, and full session recording for auditing purposes, without requiring the vendor to have direct network access to the OT environment. The PAM system acts as a secure proxy, brokering the RDP connection to the HMI. This architecture prevents direct traffic flow between IT and OT, limits the attack surface, and provides the necessary audit trail for vendor activity, which is critical for securing sensitive OT systems.
- 4
An organization is referencing NIST best practices for BCP creation while reviewing current internal organizational processes for mission-essential items.Which of the following phases establishes the identification and prioritization of critical systems and functions?
Show answer details
Correct answer: A
- 5
An organization is preparing to migrate its production environment systems from an on-premises environment to a cloud service. The lead security architect is concerned that the organization's current methods for addressing risk may not be possible in the cloud environment.Which of the following BEST describes the reason why traditional methods of addressing risk may not be possible in the cloud?
Show answer details
Correct answer: D
- 6
A company created an external application for its customers. A security researcher now reports that the application has a serious LDAP injection vulnerability that could be leveraged to bypass authentication and authorization.Which of the following actions would BEST resolve the issue? (Choose two.)
Show answer details
Correct answer: D, F
