Courseiva
mediumMultiple ChoiceObjective-mapped

CAS-004 Practice Question: A financial institution is required to comply…

A financial institution is required to comply with PCI DSS and uses a mix of legacy and modern applications. The security architect proposes to segment the network so that the cardholder data environment (CDE) is isolated. However, a legacy application in a non-CDE segment must send data to a database in the CDE. The legacy application cannot be modified and communicates via clear-text protocols. Which of the following is the most secure solution that maintains compliance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a bastion host to terminate TLS on behalf of the legacy application and forward via a one-way replication

A bastion host with TLS termination can wrap clear-text traffic in encryption, and strict firewall rules prevent direct access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Replace the legacy application immediately

    Why it's wrong here

    Not feasible in the short term; doesn't solve current need.

  • Use a bastion host to terminate TLS on behalf of the legacy application and forward via a one-way replication

    Why this is correct

    Encrypts traffic and limits the legacy application's direct access.

  • Place the legacy application in the CDE and isolate it with a firewall

    Why it's wrong here

    Expands the CDE scope and compliance burden.

  • Install a network-based DLP sensor to monitor traffic

    Why it's wrong here

    Does not encrypt or isolate; compliance requires encryption.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.