20+ practice questions focused on Security Operations — one of the most tested topics on the CompTIA SecurityX (CAS-005) exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Security Operations PracticeA security operations center (SOC) is implementing a SOAR platform to automate responses to phishing incidents. The playbook will include steps to automatically quarantine suspicious emails, delete them from user mailboxes, and block the sender's domain. Which element should the SOAR playbook incorporate to ensure the automated response does not cause unintended disruption?
Explanation: A confirmation step that prompts the analyst to approve the quarantine and deletion actions is the correct element because it introduces a human-in-the-loop (HITL) checkpoint specifically for the disruptive actions (quarantine, deletion, domain block) while still allowing the SOAR platform to automate the rest of the playbook. This balances automation speed with the need to prevent unintended disruption, such as quarantining legitimate business emails or blocking a partner domain. The confirmation step is targeted, not a blanket manual approval, so it preserves the efficiency gains of SOAR. It directly addresses the requirement to avoid unintended disruption by ensuring a human validates the high-impact actions before they execute.
A vulnerability management team is prioritizing patches for a large number of vulnerabilities discovered in a quarterly scan. A critical vulnerability in a widely used application has a CVSS base score of 9.8, but it is not currently being exploited in the wild and the application is not directly exposed to the internet. According to CVSS scoring principles, which factors should the team consider to adjust the priority?
Explanation: CVSS environmental metrics adjust the base score to reflect the specific organization's context, including collateral damage potential, target distribution, and modified impact sub-scores. Since the vulnerability is not internet-exposed, environmental metrics capture that reduced exposure and lower the effective priority. Temporal metrics address exploit maturity and remediation level, but the question emphasizes organizational context, which is environmental.
An organization is deploying deception technology to detect lateral movement by attackers. Which of the following would be the most effective to detect an attacker who has gained access to the internal network and is attempting to move to a sensitive server?
Explanation: A honeytoken is a fake credential or file designed to be accessed only by an attacker who has already compromised the network. Placing a fake password file on a file server creates a high-fidelity alert when an attacker attempts to use it for lateral movement, as legitimate users have no reason to access it. This directly detects the attacker's reconnaissance and credential harvesting behavior.
A security team is conducting a penetration test against a client's web application. During the reconnaissance phase, the tester discovers a subdomain that hosts a development version of the application with debug mode enabled. Which type of reconnaissance does this activity represent?
Explanation: Active reconnaissance involves directly interacting with the target's systems — sending DNS queries, port scans, or HTTP requests — to enumerate subdomains and services. Discovering a development subdomain with debug mode enabled required the tester to probe the target's DNS or web infrastructure, making it active reconnaissance.
A penetration tester is planning a test for a client that has a critical web application. The rules of engagement specify that the tester must avoid causing a denial of service (DoS). Which THREE actions are appropriate for the tester to include in the scope? (Select THREE.)
Explanation: Option B is correct because port scanning (e.g., with Nmap TCP SYN or connect scans) is a low-impact reconnaissance technique that identifies open services on the web server without exhausting resources or disrupting availability, so it respects the no-DoS constraint. Option D is correct because brute-forcing directories and files (e.g., with Gobuster, DirBuster, or ffuf using a wordlist) sends ordinary HTTP GET requests that enumerate hidden content and typically do not overwhelm the target if throttled, making it an appropriate discovery action. Option E is correct because testing for SQL injection in input fields (e.g., with sqlmap or manual payloads like ' OR 1=1--) targets application logic flaws and, when done carefully, does not cause a denial of service. Option A is not appropriate because social engineering against employees without prior approval violates the rules of engagement and lacks authorization. Option C is not appropriate because performing a DDoS attack directly contradicts the requirement to avoid causing a denial of service.
+15 more Security Operations questions available
Practice all Security Operations questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Security Operations. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Security Operations questions on the CAS-005 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Security Operations is tested as part of the CompTIA SecurityX (CAS-005) blueprint. Practicing with targeted Security Operations questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CAS-005 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Security Operations is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Security Operations practice session with instant scoring and detailed explanations.
Start Security Operations Practice →