Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is evaluating a CSPM tool for a multi-cloud environment. Which TWO capabilities should the architect consider essential for the CSPM? (Choose two.)

⚠ Common exam trap

CAS-005 often tests the boundary between CSPM (configuration/posture) and adjacent tools like CWPP, WAF, and DLP — candidates pick 'vulnerability scanning' or 'WAF' because they sound security-relevant, but CSPM is strictly about configuration posture and compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Continuous compliance monitoring against frameworks like CIS

Option A (Continuous compliance monitoring against frameworks like CIS) is essential because a CSPM's core purpose is to continuously assess cloud configurations against recognized benchmarks and standards such as CIS, PCI DSS, and NIST, providing ongoing assurance across the multi-cloud estate. Option C (Configuration drift detection) is also essential since CSPM must detect when resources deviate from approved secure baselines, whether through manual changes, automation, or IaC mismatches, and alert or remediate accordingly. Option B (Vulnerability scanning of container images) belongs to container/image scanning tools (e.g., Trivy, Clair) rather than CSPM, which focuses on cloud resource configuration posture. Option D (Real-time web application firewall) is a runtime application protection control typically delivered by a WAF, not a posture management function. Option E (Data loss prevention for cloud storage) is a separate data-security capability (DLP) and, while complementary, is not a defining CSPM requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Continuous compliance monitoring against frameworks like CIS

    Why this is correct

    Continuous compliance monitoring against benchmarks such as CIS satisfies the multi-cloud requirement by evaluating configurations across AWS, Azure and Google Cloud against a common control baseline, detecting drift as it occurs. This provides the ongoing assurance the architect needs, rather than a one-off point-in-time assessment.

  • ✗

    Vulnerability scanning of container images

    Why it's wrong here

    Container image vulnerability scanning inspects workloads' software packages, not cloud resource configurations, which is CSPM's domain; that belongs to container or workload scanning tools. It is tempting because CSPM findings often reference container workloads, and image scanning would be correct for a container security posture requirement.

  • ✓

    Configuration drift detection

    Why this is correct

    Configuration drift detection compares live resource state against the approved baseline and flags unauthorised changes. In a multi-cloud estate this catches manual edits and rogue deployments that policy-as-code alone would miss, maintaining the intended secure configuration.

  • ✗

    Real-time web application firewall

    Why it's wrong here

    A web application firewall inspects and filters HTTP traffic at runtime, whereas CSPM assesses configuration against benchmarks and does not sit in the request path. It is tempting because both are cloud security controls, and a WAF would be correct where the requirement is protecting web applications from exploitation.

  • ✗

    Data loss prevention for cloud storage

    Why it's wrong here

    Data loss prevention inspects and blocks sensitive data flows, a runtime content control rather than configuration posture assessment; CSPM instead detects misconfigured storage exposure. It is tempting because both address cloud storage risk, and DLP would be correct where the requirement is preventing exfiltration of regulated data.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.