Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A company is required to comply with FedRAMP for its cloud deployment. Which of the following is a key requirement for FedRAMP compliance?

⚠ Common exam trap

CAS-005 often tests the misconception that FedRAMP is just about encryption or continuous monitoring — candidates must recognise that the mandatory third-party assessment by an accredited 3PAO is the defining requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Third-party assessment by an accredited organization

FedRAMP requires that cloud service offerings undergo an independent third-party assessment by a FedRAMP-accredited Third Party Assessment Organization (3PAO) to validate security controls against NIST SP 800-53. This assessment is a cornerstone of the FedRAMP authorization process, ensuring an unbiased evaluation before a Joint Authorization Board (JAB) or agency grants an Authority to Operate (ATO). While continuous monitoring and incident response are also required, the key differentiator is the mandatory third-party assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Continuous monitoring and incident response

    Why it's wrong here

    Continuous monitoring and incident response is a FedRAMP requirement, but the stem asks for a key requirement distinguishing FedRAMP authorisation; this option describes ongoing post-authorisation activities rather than the mandatory 3PAO assessment and authorisation package. It is tempting because continuous monitoring genuinely is required, but it is not the defining requirement here.

  • ✓

    Third-party assessment by an accredited organization

    Why this is correct

    FedRAMP requires an independent assessment by a Third-Party Assessment Organization accredited under the programme, which validates the cloud service's security controls against NIST baselines before an agency can grant authorisation. This external evaluation is the key requirement the stem asks for.

  • ✗

    Implementation of AES-256 encryption for all data

    Why it's wrong here

    AES-256 encryption is one control within FedRAMP's NIST SP 800-53 baseline, not a standalone requirement; FedRAMP mandates the full 325+ control set assessed by a 3PAO, not any single cryptographic standard. It is tempting because encryption appears in the baseline, but selecting one control misrepresents FedRAMP's scope.

  • ✗

    Annual penetration testing by internal team

    Why it's wrong here

    FedRAMP requires annual assessment by an accredited Third Party Assessment Organisation (3PAO), not an internal team; internal penetration testing fails the independence requirement. It is tempting because annual testing genuinely occurs under FedRAMP, but the assessor must be independent and accredited, which an internal team is not.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.