mediumMultiple ChoiceObjective-mapped
CAS-004 Practice Question: A financial institution is required to comply…
A financial institution is required to comply with PCI DSS and uses a mix of legacy and modern applications. The security architect proposes to segment the network so that the cardholder data environment (CDE) is isolated. However, a legacy application in a non-CDE segment must send data to a database in the CDE. The legacy application cannot be modified and communicates via clear-text protocols. Which of the following is the most secure solution that maintains compliance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a bastion host to terminate TLS on behalf of the legacy application and forward via a one-way replication
A bastion host with TLS termination can wrap clear-text traffic in encryption, and strict firewall rules prevent direct access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace the legacy application immediately
Why it's wrong here
Not feasible in the short term; doesn't solve current need.
- ✓
Use a bastion host to terminate TLS on behalf of the legacy application and forward via a one-way replication
Why this is correct
Encrypts traffic and limits the legacy application's direct access.
- ✗
Place the legacy application in the CDE and isolate it with a firewall
Why it's wrong here
Expands the CDE scope and compliance burden.
- ✗
Install a network-based DLP sensor to monitor traffic
Why it's wrong here
Does not encrypt or isolate; compliance requires encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.