CAS-004 Security Architecture Practice Question
A security architect is evaluating a CSPM tool for a multi-cloud environment. Which TWO capabilities should the architect consider essential for the CSPM? (Choose two.)
⚠ Common exam trap
CAS-005 often tests the boundary between CSPM (configuration/posture) and adjacent tools like CWPP, WAF, and DLP — candidates pick 'vulnerability scanning' or 'WAF' because they sound security-relevant, but CSPM is strictly about configuration posture and compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Continuous compliance monitoring against frameworks like CIS
Option A (Continuous compliance monitoring against frameworks like CIS) is essential because a CSPM's core purpose is to continuously assess cloud configurations against recognized benchmarks and standards such as CIS, PCI DSS, and NIST, providing ongoing assurance across the multi-cloud estate. Option C (Configuration drift detection) is also essential since CSPM must detect when resources deviate from approved secure baselines, whether through manual changes, automation, or IaC mismatches, and alert or remediate accordingly. Option B (Vulnerability scanning of container images) belongs to container/image scanning tools (e.g., Trivy, Clair) rather than CSPM, which focuses on cloud resource configuration posture. Option D (Real-time web application firewall) is a runtime application protection control typically delivered by a WAF, not a posture management function. Option E (Data loss prevention for cloud storage) is a separate data-security capability (DLP) and, while complementary, is not a defining CSPM requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Continuous compliance monitoring against frameworks like CIS
Why this is correct
Continuous compliance monitoring against benchmarks such as CIS satisfies the multi-cloud requirement by evaluating configurations across AWS, Azure and Google Cloud against a common control baseline, detecting drift as it occurs. This provides the ongoing assurance the architect needs, rather than a one-off point-in-time assessment.
- ✗
Vulnerability scanning of container images
Why it's wrong here
Container image vulnerability scanning inspects workloads' software packages, not cloud resource configurations, which is CSPM's domain; that belongs to container or workload scanning tools. It is tempting because CSPM findings often reference container workloads, and image scanning would be correct for a container security posture requirement.
- ✓
Configuration drift detection
Why this is correct
Configuration drift detection compares live resource state against the approved baseline and flags unauthorised changes. In a multi-cloud estate this catches manual edits and rogue deployments that policy-as-code alone would miss, maintaining the intended secure configuration.
- ✗
Real-time web application firewall
Why it's wrong here
A web application firewall inspects and filters HTTP traffic at runtime, whereas CSPM assesses configuration against benchmarks and does not sit in the request path. It is tempting because both are cloud security controls, and a WAF would be correct where the requirement is protecting web applications from exploitation.
- ✗
Data loss prevention for cloud storage
Why it's wrong here
Data loss prevention inspects and blocks sensitive data flows, a runtime content control rather than configuration posture assessment; CSPM instead detects misconfigured storage exposure. It is tempting because both address cloud storage risk, and DLP would be correct where the requirement is preventing exfiltration of regulated data.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.