Reinforce CAS-005 concepts with active-recall study cards covering all 4 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For CAS-005 preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the CAS-005 question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your CAS-005 flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real CAS-005 exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass CAS-005.
Sample cards from the CAS-005 flashcard bank. Read the question, think of the answer, then read the explanation below.
A security analyst is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?
$1,000
The Annualized Loss Expectancy (ALE) is calculated as SLE × ARO. With an SLE of $5,000 and an ARO of 0.2, the ALE is $5,000 × 0.2 = $1,000. This represents the expected yearly financial loss from the risk event, factoring in how often it is expected to occur.
A company wants to ensure that its data handling practices align with the principle of 'privacy by design'. Which of the following actions best supports this principle?
Incorporating privacy controls during the initial system architecture
Privacy by design, codified in GDPR Article 25 and the ISO/IEC 27550 framework, requires that privacy protections be embedded into systems and processes from the outset rather than bolted on afterward. Incorporating privacy controls during initial system architecture — data minimization, purpose limitation, access controls, retention policies — is the textbook embodiment of this principle. The other options are reactive or partial measures that do not satisfy the 'by design' requirement.
A financial institution is required to comply with SOX. Which of the following is a primary focus of this regulation?
Accuracy of financial reporting and internal controls
SOX (Sarbanes-Oxley Act) primarily focuses on the accuracy of financial reporting and the effectiveness of internal controls for publicly traded companies. It mandates that management assess and report on internal controls over financial reporting, and requires external auditors to attest to those assessments. This ensures transparency and accountability in financial disclosures.
A company is implementing a zero trust architecture. Which of the following BEST describes the principle of micro-segmentation in this model?
Isolating workloads at the virtual network interface level with granular security policies
Micro-segmentation in a zero trust architecture isolates individual workloads at the virtual network interface level and enforces granular, per-workload security policies. This limits lateral movement because each workload becomes its own security zone, and traffic between workloads is explicitly allowed or denied based on identity and policy rather than network location. It is a foundational zero trust control that assumes no implicit trust based on being 'inside' the network.
An organization is adopting a cloud-first strategy and wants to ensure proper security responsibilities are understood. Which concept defines the division of security responsibilities between the cloud provider and the customer?
Shared responsibility model
The shared responsibility model defines which security tasks are handled by the provider (e.g., physical security) and which by the customer (e.g., data access).
A security architect is designing a hybrid cloud environment with workloads in AWS and on-premises. The architect needs to ensure secure, low-latency connectivity between the two environments without traversing the internet. Which solution should be used?
AWS Direct Connect
AWS Direct Connect provides dedicated private network connectivity from on-premises to AWS, offering low latency and security without internet exposure.
An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?
CRYSTALS-Kyber
CRYSTALS-Kyber is a NIST-approved post-quantum cryptographic algorithm designed for key encapsulation (KEM), selected in the NIST PQC standardization process. It is based on module learning with errors (MLWE) and provides secure key exchange resistant to quantum attacks. RSA-4096 and ECDHE are classical algorithms vulnerable to quantum computers, and CRYSTALS-Dilithium is designed for digital signatures, not key encapsulation.
An organization is implementing IPsec VPNs between sites. The security team wants to ensure data integrity and authentication but is less concerned about confidentiality for this particular link. Which IPsec protocol and mode should they use?
AH in tunnel mode
IPsec AH (Authentication Header) provides data integrity and authentication but not confidentiality (no encryption). Tunnel mode encapsulates the entire IP packet, which is suitable for site-to-site VPNs. Since confidentiality is not a concern, AH in tunnel mode is the correct choice. ESP would provide confidentiality, which is unnecessary here.
An organization wants to implement a privileged access management (PAM) solution to manage administrative credentials. They require that administrators request temporary access to privileged accounts and that these credentials are automatically rotated after each use. Which PAM approach best meets these requirements?
Just-in-time access provisioning with credential rotation
Just-in-time (JIT) access provisioning grants privileged credentials only for the duration of a task and automatically rotates or revokes them afterward, directly matching the requirement for temporary access with post-use rotation. This approach minimizes standing privileges and the attack surface. Password vaulting with checkout (A) provides temporary access but does not inherently rotate credentials after each use unless combined with rotation workflows.
A company is deploying IoT sensors that require secure firmware updates over the air (OTA). To ensure integrity and authenticity of the firmware, which of the following should be implemented?
Code signing with a trusted certificate
Code signing with a trusted certificate provides both integrity and authenticity: the firmware is hashed and signed by the vendor's private key, and the device verifies the signature using the vendor's public key. This ensures the firmware has not been tampered with and originates from a trusted source. Hash verification alone only checks integrity, not authenticity.
Which of the following certificate types is most appropriate for an organization that needs to validate the identity of individuals for email encryption and signing?
S/MIME certificate
S/MIME certificates are specifically designed for securing email. Client certificates are for authentication. Code signing is for software. DV certificates are for websites.
A security administrator is hardening SSH access to a jump host. The requirement is to allow only key-based authentication and restrict the use of weak cryptographic algorithms. Which of the following configurations accomplishes this?
Set PubkeyAuthentication yes, PasswordAuthentication no, and configure Ciphers and MACs to strong algorithms only
It explicitly enables public key authentication (PubkeyAuthentication yes), disables password-based authentication (PasswordAuthentication no), and restricts cryptographic algorithms by configuring the Ciphers and MACs directives to only strong algorithms. This directly satisfies both requirements: key-only authentication and elimination of weak crypto. The other options either leave password authentication enabled or do not address weak algorithms.
During an incident response engagement, the security team identifies that a compromised host has been communicating with multiple external IP addresses using encrypted channels. The team needs to determine which processes initiated the connections. Which type of evidence collection should be performed first to preserve the most volatile data?
Perform a memory capture using a tool like DumpIt or winpmem
Memory capture is the correct first step because running processes, active network connections, and encryption keys exist only in volatile memory (RAM) and are lost on shutdown or reboot. Tools like DumpIt or winpmem preserve this state, including the process-to-connection mapping needed to identify which process initiated the encrypted channels. The order of volatility in digital forensics dictates that RAM be collected before disk or logs, since it is the most transient evidence.
A security analyst is investigating a potential advanced persistent threat (APT) that has evaded traditional signature-based defenses. The analyst hypothesizes that the attacker is using a specific technique from the MITRE ATT&CK framework: process injection. Which threat hunting methodology is most appropriate for this scenario?
Hypothesis-driven hunting based on a specific technique (process injection) and searching for evidence in memory and process activity
Hypothesis-driven hunting is the most appropriate because the analyst has a specific, testable hypothesis: the attacker is using process injection, a known ATT&CK technique (T1055). This methodology involves proactively searching for evidence of that technique—such as anomalous memory allocations, thread execution, or API calls—rather than waiting for alerts. It directly addresses the scenario where signature-based defenses have failed, as it focuses on behavioral artifacts rather than static indicators.
During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which technique is most commonly used for lateral movement in a Windows environment?
Pass-the-Hash
Pass-the-Hash (PtH) is a credential theft technique where an attacker captures NTLM password hashes (e.g., via Mimikatz from LSASS memory) and uses them to authenticate to other Windows systems without cracking the plaintext password. It is one of the most common lateral movement techniques in Windows environments because NTLM authentication accepts the hash directly.
The CAS-005 flashcard bank covers all 4 official blueprint domains published by CompTIA. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Governance, Risk, and Compliance
Security Architecture
Security Engineering
Security Operations
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that CAS-005 questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.CAS-005 questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective CAS-005 study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free CAS-005 flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 973+ original CAS-005 flashcards across all 4 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official CompTIA exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official CAS-005 exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included