20+ practice questions focused on Security Architecture — one of the most tested topics on the CompTIA SecurityX (CAS-005) exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Security Architecture PracticeA company is deploying a cloud access security broker (CASB) to gain visibility into shadow IT. Which mode of operation would allow the CASB to inspect traffic without requiring proxy configuration on endpoints?
Explanation: API-based (out-of-band) CASB mode connects directly to sanctioned cloud services via their published APIs to scan data at rest, classify content, and detect shadow IT usage — no endpoint proxy or traffic redirection is required. Because it works through provider APIs rather than inline traffic inspection, it provides visibility without touching the endpoint network path.
A security analyst needs to ensure that only authorized containers run in a Kubernetes cluster. Which Kubernetes native security control should be configured?
Explanation: Pod Security Policies (PSPs) were the Kubernetes-native control to restrict what pods can run, including privileged containers, host namespaces, and volume types. They allowed cluster admins to define a set of conditions a pod must meet to be admitted. This directly addresses ensuring only authorized containers run.
An organization wants to enforce that only signed container images are deployed in production. Which of the following should be implemented?
Explanation: Enforcing that only signed container images are deployed requires cryptographic signing at build/push time and verification at pull/deploy time. Image signing and verification in the registry (e.g., Docker Content Trust/Notary, Sigstore Cosign, or cloud-native equivalents) provides the cryptographic guarantee of provenance and integrity. Without signing and verification, there is no way to prove an image is trusted.
A company is implementing a defense-in-depth strategy for its web application. Which THREE of the following are layers that should be included? (Select THREE.)
Explanation: Option A is correct because application-layer defenses such as a WAF and strict input validation directly protect the web app from injection, XSS, and other OWASP-style attacks, forming a key layer in defense-in-depth. Option C is correct because encrypting data at rest (e.g., AES-256 on storage) and in transit (e.g., TLS 1.2/1.3) ensures confidentiality and integrity even if perimeter or host controls are bypassed. Option D is correct because network firewalls and IDS/IPS provide perimeter and monitoring controls that detect and block malicious traffic before it reaches the application tier. Option B does not belong because SSO without MFA weakens authentication rather than adding a defensive layer, and Option E, while a valid control, is not one of the three layers the question expects for this web-application defense-in-depth scenario.
A security engineer is deploying a Cloud Access Security Broker (CASB) to protect a SaaS application. Which deployment mode allows the CASB to inspect encrypted traffic without requiring client software?
Explanation: API mode CASB deployment connects directly to the SaaS provider's public APIs (e.g., Microsoft Graph, Google Workspace APIs) using privileged credentials, allowing it to inspect data at rest, scan for sensitive content, and enforce DLP without any client software or inline traffic interception. Because it works out-of-band via APIs, it can see encrypted SaaS data after the provider decrypts it, without needing to break TLS itself. This matches the requirement of inspecting encrypted traffic without client software.
+15 more Security Architecture questions available
Practice all Security Architecture questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Security Architecture. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Security Architecture questions on the CAS-005 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Security Architecture is tested as part of the CompTIA SecurityX (CAS-005) blueprint. Practicing with targeted Security Architecture questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CAS-005 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Security Architecture is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Security Architecture practice session with instant scoring and detailed explanations.
Start Security Architecture Practice →