CAS-004 Security Architecture Practice Question
A security architect is designing a system that must detect tampering with archived audit logs even if an attacker later gains administrative access to the log storage. The logs must remain verifiable for seven years without exposing their contents to the storage provider. Which design BEST meets these requirements?
⚠ Common exam trap
The trap here is assuming immutability features such as object locks or versioning provide tamper evidence, when they only restrict deletion and overwrite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compute a hash chain over log entries, sign each checkpoint with a private key held in an offline hardware security module, and encrypt logs with keys the provider cannot access.
Tamper-evident archival requires cryptographic binding of entries plus signatures produced with a key the attacker cannot reach, combined with encryption whose keys the storage provider does not hold. Hash chains detect alteration, offline hardware security module signing prevents forgery of new checkpoints, and provider-inaccessible keys preserve confidentiality across the retention period.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt each log file with a symmetric key stored alongside the files and rely on file permissions to prevent modification.
Why it's wrong here
Storing the encryption key with the data means an attacker with administrative access can decrypt and re-encrypt altered logs, defeating tamper detection. File permissions are also ineffective against an administrator, so the design fails the requirement to detect tampering after privileged compromise.
- ✗
Upload plaintext logs to object storage with versioning enabled and enable a write-once retention lock on the bucket.
Why it's wrong here
Retention locks and versioning deter deletion and overwrite but do not prevent an administrator from writing modified content as a new version, nor do they detect it. Plaintext storage also exposes log contents to the provider, violating the confidentiality requirement.
- ✗
Replicate logs to a second region and compare file checksums between regions during quarterly audits.
Why it's wrong here
Cross-region replication improves durability but an attacker with administrative access can alter both copies, and quarterly comparison leaves a long detection gap. Checksums computed without a protected signing key can also be recomputed by the attacker, so tampering may go undetected.
- ✓
Compute a hash chain over log entries, sign each checkpoint with a private key held in an offline hardware security module, and encrypt logs with keys the provider cannot access.
Why this is correct
A hash chain makes any alteration detectable because it breaks subsequent links, while offline hardware security module signing prevents an attacker with storage access from forging new checkpoints. Encrypting with keys unavailable to the provider keeps contents confidential, satisfying all stated requirements simultaneously.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.