CompTIA · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
20% of exam · 6 sample questions below
A security analyst is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?
$0
$5,200
$1,000
Multiplying SLE by ARO gives $5,000 × 0.2 = $1,000, the annualised loss expectancy. This satisfies the stem's requirement to quantify expected yearly loss from the server risk, expressing exposure as a single monetary figure rather than a frequency or per-incident cost.
$25,000
A company wants to ensure that its data handling practices align with the principle of 'privacy by design'. Which of the following actions best supports this principle?
Incorporating privacy controls during the initial system architecture
Embedding privacy controls at the initial system architecture stage satisfies privacy by design, which requires data protection to be built into systems from the outset rather than bolted on after deployment. Retrofitting later cannot match this preventative, architecture-level alignment.
Encrypting data at rest only
Performing an annual privacy audit
Providing privacy training to employees
A financial institution is required to comply with SOX. Which of the following is a primary focus of this regulation?
Privacy of personal data for EU citizens
Accuracy of financial reporting and internal controls
SOX focuses on the accuracy and reliability of financial reporting and the effectiveness of internal controls over financial reporting for publicly traded companies. This directly matches the financial institution's compliance obligation, distinguishing it from regulations centred on privacy or payment card data.
Security of health information
Protection of cardholder data
An organization has identified a vulnerability in a legacy system that cannot be patched. The system is critical for operations, and the cost of mitigating the vulnerability exceeds the potential loss. Which risk treatment option is most appropriate?
Risk acceptance
Acceptance fits because the legacy system cannot be patched, remains operationally critical, and the mitigation cost exceeds the potential loss. Retaining the residual risk formally, with documented sign-off and monitoring, is the proportionate treatment rather than transfer, avoidance or further mitigation.
Risk avoidance
Risk mitigation
Risk transfer
A security manager is evaluating two risk quantification approaches: Factor Analysis of Information Risk (FAIR) and a qualitative heat map. Which of the following is a key advantage of using FAIR over the qualitative heat map?
FAIR is the only framework recognized by NIST
FAIR is easier to communicate to non-technical stakeholders
FAIR requires less data and expertise to implement
FAIR provides a monetary value for risk, enabling ROI calculations
FAIR quantifies risk in monetary terms by modelling loss event frequency and loss magnitude, producing annualised loss exposure. This contrasts with qualitative heat maps that rank risks ordinally, and enables cost-benefit and ROI comparisons of proposed security controls.
During a vendor risk assessment, a company receives a SOC 2 Type II report from a cloud service provider. What does this report primarily attest to?
The design and operating effectiveness of controls over a period of time
SOC 2 Type II evaluates control design and operating effectiveness across a defined audit period, unlike Type I which reports design at a single point in time. This satisfies the vendor assessment requirement for sustained control performance evidence.
The vendor's financial stability
The vendor's compliance with privacy laws
The vendor's penetration test results
Want more Governance, Risk, and Compliance practice?
Practice this domain27% of exam · 6 sample questions below
A company is implementing a zero trust architecture. Which of the following BEST describes the principle of micro-segmentation in this model?
Creating a single perimeter around the entire network
Isolating workloads at the virtual network interface level with granular security policies
Micro-segmentation creates granular, workload-level security policies enforced at each virtual network interface, so lateral movement between workloads is blocked regardless of subnet boundaries. This satisfies zero trust's requirement to isolate individual workloads rather than trusting the network perimeter.
Using VLANs to separate departments
Implementing a VPN for remote access
An organization is adopting a cloud-first strategy and wants to ensure proper security responsibilities are understood. Which concept defines the division of security responsibilities between the cloud provider and the customer?
Zero trust
Shared responsibility model
The shared responsibility model defines the security boundary between provider and customer, satisfying the cloud-first scenario's need to clarify who secures what. The provider secures the cloud infrastructure, while the customer secures data, identities, and access in the cloud. This division varies by service model (IaaS, PaaS, SaaS), directly answering the stem's requirement.
Software-defined perimeter
Defense in depth
A security architect is designing a hybrid cloud environment with workloads in AWS and on-premises. The architect needs to ensure secure, low-latency connectivity between the two environments without traversing the internet. Which solution should be used?
AWS Direct Connect
AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, bypassing the public internet entirely. This satisfies both constraints in the stem: low latency, since traffic avoids internet routing variability, and security, since data never traverses public infrastructure. Site-to-Site VPN would encrypt traffic but still traverse the internet, failing the no-internet requirement.
Site-to-site VPN over the internet
AWS Client VPN
AWS Transit Gateway with internet gateway
An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?
RSA-4096
CRYSTALS-Kyber
CRYSTALS-Kyber is a lattice-based key encapsulation mechanism (KEM), standardised by NIST as ML-KEM, which secures symmetric keys through public-key encryption. It directly satisfies the stem's requirement for a post-quantum algorithm designed for key encapsulation, unlike CRYSTALS-Dilithium or SPHINCS+, which are digital signature schemes.
ECDHE
CRYSTALS-Dilithium
During a security assessment, a penetration tester discovers that a web application fails to validate the size of user input, leading to a buffer overflow. Which application security control would have BEST prevented this vulnerability?
Input validation
Input validation enforces length and format checks on user-supplied data before processing, directly satisfying the constraint that input size must be bounded. By rejecting oversized payloads at the boundary, it prevents the buffer overflow the penetration tester exploited, whereas output encoding or parameterised queries address different vulnerability classes.
Static application security testing (SAST)
Web application firewall (WAF)
Rate limiting
A company is deploying a SASE architecture. Which component is responsible for securing web traffic and enforcing acceptable use policies at the edge?
Zero Trust Network Access (ZTNA)
Secure Web Gateway (SWG)
Secure Web Gateway sits at the edge and inspects outbound web traffic, enforcing acceptable use policies, URL filtering and threat protection. It satisfies the stem's requirement to secure web traffic and apply acceptable use controls within the SASE architecture.
Cloud Access Security Broker (CASB)
SD-WAN
Want more Security Architecture practice?
Practice this domain31% of exam · 6 sample questions below
An organization is implementing IPsec VPNs between sites. The security team wants to ensure data integrity and authentication but is less concerned about confidentiality for this particular link. Which IPsec protocol and mode should they use?
ESP in tunnel mode
AH in tunnel mode
AH provides data integrity and origin authentication through its ICV, but performs no encryption, matching the stated indifference to confidentiality. Tunnel mode encapsulates the entire original IP packet, protecting traffic between the two site gateways rather than just host-to-host flows.
AH in transport mode
ESP in transport mode
An organization wants to implement a privileged access management (PAM) solution to manage administrative credentials. They require that administrators request temporary access to privileged accounts and that these credentials are automatically rotated after each use. Which PAM approach best meets these requirements?
Password vaulting with checkout
Just-in-time access provisioning with credential rotation
Just-in-time access provisioning grants privileged accounts only for an approved, time-bound window, and credential rotation replaces the password after each session. Together these satisfy both stated requirements: temporary access on request and automatic rotation following use.
Privileged account session management
Break-glass account procedures
A company is deploying IoT sensors that require secure firmware updates over the air (OTA). To ensure integrity and authenticity of the firmware, which of the following should be implemented?
Code signing with a trusted certificate
Code signing with a trusted certificate lets each IoT sensor verify the firmware's signature against the vendor's public key before installation, confirming both integrity and origin. Unsigned or tampered images are rejected, satisfying the OTA authenticity requirement.
Secure boot on the device
Hash verification only
Encryption of the firmware image
Which of the following certificate types is most appropriate for an organization that needs to validate the identity of individuals for email encryption and signing?
S/MIME certificate
S/MIME certificates bind an individual's verified identity to a public key, enabling message signing and encryption within mail clients. This validates the sender's identity for email, precisely matching the stated requirement for individual identity validation.
Domain Validation (DV) certificate
Client authentication certificate
Code signing certificate
A security administrator is hardening SSH access to a jump host. The requirement is to allow only key-based authentication and restrict the use of weak cryptographic algorithms. Which of the following configurations accomplishes this?
Set PermitRootLogin prohibit-password and PasswordAuthentication yes
Set PubkeyAuthentication yes, PasswordAuthentication no, and configure Ciphers and MACs to strong algorithms only
Disabling PasswordAuthentication enforces key-only access, satisfying the key-based constraint, while explicitly restricting Ciphers and MACs to strong algorithms removes weak cryptographic suites. Together these directives harden the SSH daemon against both password brute force and downgrade attacks on the jump host.
Set PasswordAuthentication yes and use a strong password policy
Set AuthenticationMethods publickey,keyboard-interactive
An organization is implementing a PKI to issue certificates for internal applications. The security team wants to minimize the risk of compromise to the root CA. Which of the following is the BEST practice to protect the root CA?
Delegate root CA responsibilities to a public CA
Keep the root CA offline and store its private key in a hardware security module
An offline root CA, with its private key held in a hardware security module, is unreachable from the network, so compromise of issuing or web servers cannot expose it. This directly minimises the risk the security team wants to avoid.
Install the root CA on a VM with strict firewall rules
Use a self-signed certificate for the root CA and distribute it manually
Want more Security Engineering practice?
Practice this domain22% of exam · 6 sample questions below
During an incident response engagement, the security team identifies that a compromised host has been communicating with multiple external IP addresses using encrypted channels. The team needs to determine which processes initiated the connections. Which type of evidence collection should be performed first to preserve the most volatile data?
Export the Windows event logs related to network activity
Execute a network scan from the compromised host to identify active connections
Capture a full disk image using FTK Imager
Perform a memory capture using a tool like DumpIt or winpmem
RAM holds running processes, open sockets and encryption keys, and is lost on shutdown or reboot. Capturing memory first with DumpIt or winpmem preserves the process-to-connection mapping the team needs, satisfying the requirement to collect the most volatile evidence before disk artefacts.
A security analyst is investigating a potential advanced persistent threat (APT) that has evaded traditional signature-based defenses. The analyst hypothesizes that the attacker is using a specific technique from the MITRE ATT&CK framework: process injection. Which threat hunting methodology is most appropriate for this scenario?
TTP-driven hunting by analyzing adversary behaviors mapped to the ATT&CK framework
Hypothesis-driven hunting based on a specific technique (process injection) and searching for evidence in memory and process activity
Hypothesis-driven hunting tests the specific process injection technique by examining memory and process activity for injected code, hollowed processes or anomalous API calls. This targeted approach suits an APT that evades signature-based defences, since it searches for behavioural evidence rather than known indicators.
Automated hunting using SIEM correlation rules that trigger on known malicious file hashes
IoC-driven hunting using known indicators of compromise from open-source feeds
During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which technique is most commonly used for lateral movement in a Windows environment?
SQL injection
Cross-site scripting (XSS)
Pass-the-Hash
Pass-the-Hash reuses captured NTLM password hashes to authenticate to remote Windows systems without cracking the plaintext password, enabling lateral movement between hosts. This satisfies the scenario's Windows lateral-movement requirement by leveraging credential material already obtained during initial access.
ARP spoofing
A security analyst is reviewing logs from a SIEM and notices that a user account has been successfully authenticated from two different geographic locations within a short time span, which is impossible. The SIEM uses user behavior analytics (UBA). What type of anomaly is this most likely to detect?
A credential theft and reuse incident
Impossible travel is the classic UBA signal: the same credentials authenticating from two distant locations faster than physical travel allows. This pattern indicates the account's credentials have been compromised and reused by an attacker, directly matching the impossible-login constraint described in the stem.
A misconfigured VPN that routes traffic through multiple gateways
A brute-force attack on the user account
A man-in-the-middle attack intercepting the authentication
Which of the following best describes the purpose of the STIX and TAXII standards in threat intelligence sharing?
They are tools for analyzing malware behavior in a sandbox environment
They are used to automatically patch vulnerabilities based on threat feeds
They provide a framework for conducting incident response exercises
They standardize the format and exchange of cyber threat intelligence
STIX defines a structured language for describing threat indicators, actors and campaigns, while TAXII specifies the transport protocol for exchanging that content between systems. Together they give vendors and sharing communities a common format and delivery mechanism for cyber threat intelligence.
During a digital forensics investigation of a compromised Linux server, the investigator needs to preserve the evidence in a forensically sound manner. The server is still running. Which of the following should the investigator do first?
Pull the power cord to preserve the disk state
Create a forensic image of the hard drive using dd over a network connection
Run the 'history' command to see recent user commands
Capture the contents of RAM using a tool like LiME or fmem
RAM contents are volatile and lost on shutdown, so capturing memory with LiME or fmem first preserves evidence that would otherwise vanish. Order of volatility demands memory acquisition before disk imaging on a live system.
Want more Security Operations practice?
Practice this domainThe CAS-005 exam has 90 questions and must be completed in 165 minutes. The passing score is 700/1000.
Advanced scenario questions on enterprise security architecture, cryptography, governance, risk management, and integration of security controls. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 4 domains: Governance, Risk, and Compliance, Security Architecture, Security Engineering, Security Operations. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official CompTIA CAS-005 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.