Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4,6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 65 pages
Exam (elaborations)

LATEST COMPTIA CASP+ (CAS-004) EXAM BANK | COMPLETE EXAM BANK WITH CORRECT ANSWERS AND RATIONALES. A+ GRADED

Document preview thumbnail
Preview 4 out of 65 pages

LATEST COMPTIA CASP+ (CAS-004) EXAM BANK | COMPLETE EXAM BANK WITH CORRECT ANSWERS AND RATIONALES. A+ GRADED

Content preview

LATEST COMPTIA CASP+ (CAS-004) EXAM
BANK | COMPLETE EXAM BANK WITH
CORRECT ANSWERS AND RATIONALES.
A+ GRADED


1. An enterprise security architect is designing a
solution to protect against data exfiltration via DNS
tunneling. Which control is most effective?
A) Blocking all outbound DNS traffic
B) Implementing DNS over TLS (DoT) with DNS
filtering and analyzing DNS query length and entropy
C) Allowing only recursive queries to internal DNS
servers with strict response size limits
D) Disabling DNS logging
Correct answer: B
Rationale: DoT encrypts DNS queries but does not
prevent tunneling. The most effective control is a
secure DNS gateway that inspects query length,
frequency, and subdomain entropy.


2. A security analyst is implementing a zero trust
architecture. Which of the following best describes
the core principle of zero trust?

,A) Trust but verify once at the perimeter
B) Never trust, always verify. All traffic (inside and
outside the network) is treated as untrusted
C) Trust all internal traffic and only verify external
traffic
D) Use a single factor of authentication
Correct answer: B
Rationale: Zero trust assumes no implicit trust
(internal or external). Every request is authenticated,
authorized, and encrypted regardless of location.


3. An organization is migrating to a multi-cloud
environment (AWS, Azure, and GCP). Which of the
following is a primary security concern when using
multiple cloud providers?
A) Inconsistent identity and access management
(IAM) policies across providers
B) Higher bandwidth costs
C) Increased storage capacity
D) Lack of encryption options
Correct answer: A
Rationale: Each cloud provider has its own IAM
model. Consistent policy enforcement and

,centralized identity management (federation, SSO,
SCIM) across multi-cloud is challenging.


4. A security architect is evaluating a secure SDLC
approach. In which phase should threat modeling
(e.g., STRIDE, PASTA) be performed?
A) Design phase
B) Deployment phase
C) Maintenance phase
D) Incident response phase
Correct answer: A
Rationale: Threat modeling is performed during the
design phase to identify potential threats, attack
surfaces, and mitigations before code is written.


5. An organization needs to implement a
cryptographic solution that provides non-repudiation
for sensitive transactions. Which type of algorithm
should be used?
A) Symmetric encryption (AES)
B) Hashing (SHA-256)
C) Asymmetric encryption (digital signatures using
RSA or ECDSA)

, D) Steganography
Correct answer: C
Rationale: Digital signatures (asymmetric) provide
non-repudiation because only the signer's private key
can create the signature, and the public key verifies
it.


6. A company is required to comply with PCI DSS.
Which of the following is a requirement for protecting
cardholder data?
A) Storing full magnetic stripe data and CVV after
authorization
B) Encrypting cardholder data at rest and in transit
using strong cryptography
C) Allowing all employees access to cardholder data
D) Logging access but not monitoring logs
Correct answer: B
Rationale: PCI DSS requires encryption of stored
cardholder data (tokenization may substitute) and
encrypted transmission. CVV and full track data
cannot be stored after authorization.


7. A security analyst is investigating a potential
container breakout incident in a Kubernetes cluster.

Document information

Uploaded on
May 30, 2026
Number of pages
65
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$23.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
IsaacRobie
4.0
(78)
Sold
341
Followers
156
Items
4377
Last sold
1 month ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can immediately select a different document that better matches what you need.

Pay how you prefer, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card or EFT and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions