CAS-004 Security Engineering Practice Question
A security architect is designing segmentation for an industrial control network that runs Modbus/TCP between engineering workstations and programmable logic controllers. The architect wants to prevent an attacker who compromises a workstation from issuing unauthorized write commands to the controllers, while avoiding disruption of legitimate polling traffic. Which control BEST addresses the specific risk?
⚠ Common exam trap
The trap here is trusting port-based or identity-based controls to stop malicious commands, when only protocol-aware inspection can distinguish a read from a write.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a deep packet inspection device that understands the protocol and blocks write function codes from workstations.
The risk is a compromised workstation sending unauthorized write commands over a legitimate protocol. Only a control that inspects the industrial protocol at the application layer can distinguish reads from writes and block the dangerous function codes while allowing polling. Address, port, and device-authentication controls operate below that layer and cannot enforce command-level policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply network address translation so controllers are not directly reachable from the workstation subnet.
Why it's wrong here
NAT changes addressing and can hide topology, but it does not stop a workstation that can still route to the translated address from issuing writes. It provides no protocol-level filtering of function codes. This control offers obfuscation rather than enforcement of what commands are permitted, so it fails the stated requirement.
- ✗
Enable 802.1X port-based authentication on the switches that connect the controllers.
Why it's wrong here
802.1X authenticates devices before granting network access, but a compromised workstation that already passed authentication retains its authorized port and can still send write commands. Port authentication does not inspect protocol payloads or function codes. It addresses unauthorized network attachment rather than the risk of malicious commands from a trusted host.
- ✓
Implement a deep packet inspection device that understands the protocol and blocks write function codes from workstations.
Why this is correct
A protocol-aware inspection device parses Modbus/TCP function codes and can permit read or polling functions while dropping write functions from engineering workstations. This directly constrains what a compromised workstation can do to the controllers without blocking legitimate polling. Because it operates at the application layer of the industrial protocol, it addresses the specific unauthorized write risk.
- ✗
Deploy a stateful firewall that permits only the workstation-to-controller TCP port used by the protocol.
Why it's wrong here
A stateful firewall permitting the Modbus port still allows any function code, including write commands, because it inspects only addresses and ports. A compromised workstation would retain full ability to issue unauthorized writes. This control reduces exposure to other hosts but does not address the specific risk of malicious write operations from an already-compromised workstation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.