exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 37 discussion

Actual exam question from CompTIA's CAS-004
Question #: 37
Topic #: 1
[All CAS-004 Questions]

A new web server must comply with new secure-by-design principles and PCI DSS. This includes mitigating the risk of an on-path attack. A security analyst is reviewing the following web server configuration:

Which of the following ciphers should the security analyst remove to support the business requirements?

  • A. TLS_AES_128_CCM_8_SHA256
  • B. TLS_DHE_DSS_WITH_RC4_128_SHA
  • C. TLS_CHACHA20_POLY1305_SHA256
  • D. TLS_AES_128_GCM_SHA256
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
23169fd
10 months, 3 weeks ago
Selected Answer: B
This cipher suite uses RC4 encryption, which is considered insecure and has known vulnerabilities that make it susceptible to attacks. The RC4 algorithm has been deprecated and should not be used in any secure communications. Removing this cipher suite aligns with secure-by-design principles and PCI DSS requirements.
upvoted 2 times
...
BiteSize
1 year, 10 months ago
Selected Answer: B
RC4 is BAD! Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 3 times
Zulunation
1 year, 9 months ago
WHEN DO YOU TAKE THE EXAM
upvoted 2 times
Uncle_Lucifer
1 year, 9 months ago
He already took it and passed.
upvoted 8 times
...
...
...
margomi86
2 years, 2 months ago
Selected Answer: B
The TLS_DHE_DSS_WITH_RC4_128_SHA cipher should be removed from the web server configuration since it uses the insecure RC4 encryption algorithm, which is vulnerable to on-path attacks. Therefore, the answer is B.
upvoted 1 times
...
jan2134
2 years, 2 months ago
Selected Answer: B
In the past, RC4 was advised as a way to mitigate BEAST attacks. However, due to the latest attacks on RC4, Microsoft has issued an advisory against it. The PCI DSS also prohibits the use of the RC4 bulk cipher. https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/#:~:text=In%20the%20past%2C%20RC4%20was%20advised%20as%20a,prohibits%20the%20use%20of%20the%20RC4%20bulk%20cipher.
upvoted 4 times
...
FOURDUE
2 years, 4 months ago
Selected Answer: B
This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections.
upvoted 2 times
...
adamwella
2 years, 8 months ago
Selected Answer: B
TLS 1.1 uses RC4 so its the most outdated of all the choices. Answer is B
upvoted 3 times
...
Sloananne
2 years, 8 months ago
Selected Answer: B
B is the only unsecure
upvoted 1 times
...
adamwella
2 years, 8 months ago
Where is the contributor admins on these questions. Is clearly B yet we have trolls selecting the wrong answers.
upvoted 1 times
...
[Removed]
2 years, 10 months ago
Selected Answer: B
RC4 is deprecated
upvoted 3 times
...
RevZig67
3 years ago
Selected Answer: B
RC4 is the clue here.
upvoted 3 times
...
zerocool3166
3 years, 2 months ago
B. Is the answer. Additionally, use of weak cipher suites or unapproved algorithms – e.g., RC4, MD5, and others – is not allowed. https://blog.pcisecuritystandards.org/are-you-ready-for-30-june-2018-sayin-goodbye-to-ssl-early-tls
upvoted 2 times
...
majestrate
3 years, 3 months ago
This is the only reference I could find: https://datatracker.ietf.org/doc/html/rfc7465 This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections.
upvoted 2 times
...
willsy
3 years, 3 months ago
RC4 is depricated.
upvoted 2 times
...
justx
3 years, 3 months ago
Think it's B. Because it says just 'SHA' at the end, which implies SHA 1
upvoted 3 times
...
patinho777
3 years, 4 months ago
Can someone explain why? Thanks!
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...