easyMultiple Choice
CAS-004 Practice Question: A security administrator needs to automate the…
A security administrator needs to automate the process of revoking access for terminated employees across multiple cloud services. Which scripting approach would best minimize the risk of errors and ensure consistent execution?
⚠ Common exam trap
The exam often tests the misconception that any scripting approach (e.g., Python or shell) is sufficient for automation, but the trap is that they ignore the critical need for secure credential management and idempotent execution, which configuration management tools like Ansible are specifically designed to provide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a configuration management tool like Ansible with a playbook that calls cloud provider modules using encrypted vault files for credentials.
Ansible playbooks with encrypted vault files provide idempotent, repeatable automation across multiple cloud services without exposing credentials in plaintext. The use of dedicated cloud provider modules (e.g., aws_iam, gcp_iam) abstracts API complexities and ensures consistent revocation logic, minimizing human error compared to ad-hoc scripting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a shell script that relies on environment variables containing API keys.
Why it's wrong here
Environment variables expose API keys to any process on the host and provide no rotation, auditing or scoping, so revocation consistency and error reduction are not guaranteed. The approach tempts for quick local automation, but it suits only single-operator, low-sensitivity tasks where a managed identity or vault is unavailable.
- ✓
Use a configuration management tool like Ansible with a playbook that calls cloud provider modules using encrypted vault files for credentials.
Why this is correct
Ansible playbooks execute idempotently across cloud modules, so revocations run consistently regardless of prior state, while encrypted vault files keep credentials out of plaintext. This minimises manual error and satisfies the consistent, secure execution requirement.
- ✗
Write a Python script using separate API calls for each service with hardcoded credentials.
Why it's wrong here
Hardcoded credentials embed secrets in source and per-service API calls lack central orchestration, so a partial failure leaves accounts active without rollback. The approach tempts because Python offers broad SDK support, yet it is correct only where a secrets manager supplies credentials and idempotent orchestration handles retries.
- ✗
Manually execute commands each time an employee is terminated.
Why it's wrong here
Manual process is slow and error-prone.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.