CAS-004 Security Architecture Practice Question
A security architect at a financial services firm must ensure that virtual machine workloads on a private cloud cannot execute unauthorized binaries, even if an attacker gains root access. The solution must enforce policy at the hypervisor layer without relying on agents inside the guest OS. Which of the following should the architect implement?
⚠ Common exam trap
The trap here is assuming that any endpoint security tool running inside the guest OS can enforce policy against a root-level attacker.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Virtual machine introspection (VMI) with hypervisor-enforced integrity monitoring
Hypervisor-based introspection enforces policy outside the guest OS, so even root-level malware cannot disable the control. It provides tamper-resistant visibility and can prevent execution of unauthorized binaries, meeting the agentless and root-resistant requirements. Agent-based tools and log correlation are either bypassable or detective only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Virtual machine introspection (VMI) with hypervisor-enforced integrity monitoring
Why this is correct
VMI allows the hypervisor to inspect guest memory and CPU state from outside the VM, so policy enforcement cannot be bypassed by root-level attackers inside the guest. It monitors integrity and can block execution of unauthorized binaries at the hypervisor layer, satisfying the agentless and root-resistant requirements described in the scenario.
- ✗
File integrity monitoring (FIM) of /usr/bin on each virtual machine
Why it's wrong here
FIM detects changes to files but does not block execution of unauthorized binaries. It also typically runs as an agent inside the guest, which a root attacker can disable. The scenario demands hypervisor-layer prevention, so FIM alone is insufficient.
- ✗
Security information and event management (SIEM) correlation with guest OS logs
Why it's wrong here
SIEM correlation analyzes logs after events occur; it is detective and does not prevent binary execution. Guest OS logs can also be altered or suppressed by a root-level attacker. This approach fails the preventive and tamper-resistant requirements of the scenario.
- ✗
Host-based intrusion prevention system (HIPS) installed on each guest OS
Why it's wrong here
A HIPS agent runs inside the guest OS and depends on the guest kernel for enforcement. An attacker with root access can disable, unload, or tamper with the agent, defeating the control. The scenario explicitly requires enforcement without relying on in-guest agents, so a HIPS does not meet the stated requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.