Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A healthcare organization is architecting a secure data exchange with a partner hospital. The partners need to share patient records in near real time, but they do not want to expose their internal databases directly. The security architect must ensure that only specific, authorized fields are exchanged, that the data is validated against a predefined schema, and that the exchange is auditable and resistant to tampering. Which approach best satisfies these requirements?

⚠ Common exam trap

The trap here is underestimating the need for schema validation and message signing, and assuming that any encrypted transport such as a VPN or SFTP is sufficient for secure data exchange.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A mutually authenticated API gateway with schema validation and signed messages

A mutually authenticated API gateway with schema validation and signed messages enables selective field exchange, real-time communication, strict schema enforcement, and tamper-resistant auditing. It avoids exposing internal databases and provides the necessary security controls for partner data sharing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A shared message queue using AMQP with no message signing

    Why it's wrong here

    A shared message queue can enable near real-time exchange, but without message signing it does not provide tamper resistance or non-repudiation. It also does not inherently enforce schema validation or restrict which fields are exchanged unless additional application-level controls are implemented. The requirement for auditability and tamper resistance is not met.

  • ✓

    A mutually authenticated API gateway with schema validation and signed messages

    Why this is correct

    A mutually authenticated API gateway allows the partners to expose only specific endpoints and fields, enforce schema validation, and log all exchanges for auditability. Digital signatures on messages provide tamper resistance and non-repudiation. This approach avoids direct database exposure and meets the real-time, least-privilege, and audit requirements.

  • ✗

    SFTP file drops of full database exports on a scheduled basis

    Why it's wrong here

    SFTP file drops are batch-oriented and do not provide near real-time exchange. They also typically involve full database exports, which violate the requirement to exchange only specific authorized fields. While SFTP can be secured, it lacks schema validation and per-transaction auditability, and it does not prevent tampering of the file contents.

  • ✗

    Direct database replication between the two organizations over a VPN

    Why it's wrong here

    Direct database replication exposes the internal database schema and potentially all data, not just authorized fields. It also lacks schema validation at the field level and does not provide a clear audit trail of individual exchanges. While a VPN encrypts transit, replication does not enforce least-privilege data sharing or tamper resistance.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.